
<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Control Plane ]]></title><description><![CDATA[Insights and analysis from Kiteworks for cybersecurity, compliance, and risk management leaders working to control, monitor, and protect every data interaction between humans and AI agents.]]></description><link>https://kiteworks.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!-Fqi!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd563556a-3610-4760-a881-1a941423f056_257x257.png</url><title>The Control Plane </title><link>https://kiteworks.substack.com</link></image><generator>Substack</generator><lastBuildDate>Mon, 14 Sep 2026 11:28:20 GMT</lastBuildDate><atom:link href="https://kiteworks.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Kiteworks]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[kiteworks@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[kiteworks@substack.com]]></itunes:email><itunes:name><![CDATA[Kiteworks]]></itunes:name></itunes:owner><itunes:author><![CDATA[Kiteworks]]></itunes:author><googleplay:owner><![CDATA[kiteworks@substack.com]]></googleplay:owner><googleplay:email><![CDATA[kiteworks@substack.com]]></googleplay:email><googleplay:author><![CDATA[Kiteworks]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[A Patched SharePoint Bug Still Got Exploited in a Day.]]></title><description><![CDATA[The patch was not the problem. The trust model was.]]></description><link>https://kiteworks.substack.com/p/a-patched-sharepoint-bug-still-got</link><guid isPermaLink="false">https://kiteworks.substack.com/p/a-patched-sharepoint-bug-still-got</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Fri, 11 Sep 2026 15:01:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vlLJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vlLJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vlLJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!vlLJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!vlLJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!vlLJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vlLJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:541381,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/214968550?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vlLJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!vlLJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!vlLJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!vlLJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F471d8574-145a-47b5-b01a-d3ce3cf9fe5e_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On August 11, Rapid7&#8217;s Stephen Fewer <a href="https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed/">published proof-of-concept code</a> for CVE-2026-55040, a JWT authentication bypass in on-premises Microsoft SharePoint Server. Microsoft had shipped the fix a month earlier, on July 14. Researcher Defused <a href="https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/">clocked the code being used in live attacks the next day</a>. That is not the story. Patches lag exploitation constantly; nobody&#8217;s surprised by that anymore. The story is what happened two weeks later, on August 24, when VulnCheck&#8217;s Jonathan Peterson <a href="https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce">dropped a second exploit</a> for a completely different flaw, CVE-2026-63520, and the two chained into full remote code execution on any server that hadn&#8217;t closed both.</p><p>Two independent bugs, disclosed weeks apart, by two different research teams, became one weapon the moment someone had the patience to connect them. That is the actual thesis here. Your patch inventory tracks CVEs one at a time. Attackers don&#8217;t.</p><h3><span>What Actually Happened</span></h3><p>CVE-2026-55040 breaks JWT token validation badly enough that an attacker with zero <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> can forge a session and act as a SharePoint site user, or a site administrator. No password, no <a href="http://kiteworks.com/risk-compliance-glossary/phishing-attacks/">phishing</a>, no prior foothold. CVE-2026-63520, rated CVSS 8.1, lives somewhere entirely different. It sits inside SharePoint&#8217;s Business Connectivity Services, the integration layer that talks to external line-of-business systems. VulnCheck traced the root cause to an unsafe .NET type instantiation, exploitable through a deserialization gadget chain built on <span>System.Web.UI.LosFormatter</span>. On its own, that is an obscure finding a patch-management dashboard would rank somewhere below &#8220;nice to fix eventually.&#8221;</p><p>Chain it behind an authentication bypass and it stops being obscure. CVE-2026-55040 gets you in the door. CVE-2026-63520 gets you code execution once you&#8217;re inside. Neither <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> is remarkable in isolation. The chain is what turns two medium-priority tickets into a full server compromise.</p><h3><span>The Pattern You&#8217;ve Seen Before, Under Different CVE Numbers</span></h3><p>This exact shape, authentication bypass chained into an integration or deserialization flaw for unauthenticated RCE, already burned SharePoint Server once, in 2025, in the campaign researchers called &#8220;ToolShell.&#8221; <a href="https://unit42.paloaltonetworks.com/microsoft-sharepoint-cve-2025-49704-cve-2025-49706-cve-2025-53770/">Palo Alto Networks&#8217; Unit 42 studied that wave</a> and landed on a sentence every security team should have tattooed somewhere visible, &#8220;Patching alone is insufficient to fully evict the threat.&#8221; Attackers in that campaign moved laterally after initial access and, in documented cases, stole IIS machine key material on the way through, <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> that outlive both the patch and the removal of whatever web shell got planted.</p><p>A year later, different CVE numbers, same platform, same outcome. That is not bad luck. That is what happens when a platform&#8217;s authentication layer grants durable, session-based trust instead of checking every request against policy. Forge the session once and you own everything the session can touch, indefinitely, until someone thinks to revoke it.</p><h3><span>Why the Math Got Worse This Year</span></h3><p>Here&#8217;s the part that should worry you more than either CVE number. The <a href="https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/">2026 Verizon Data Breach Investigations Report</a> found that <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerability</a> exploitation is now the single most common way attackers get in, present in 31% of breaches, up from 20% the year before. That&#8217;s a 55% jump in twelve months. Over the same stretch, the median time to patch went from 32 days to 43 days, and only 26% of vulnerabilities on the <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities catalog</a> got fully remediated in 2025, down from 38% the year before.</p><p>Sit with that. Exploitation is accelerating. Remediation is getting slower. Those two lines are moving in opposite directions, and the gap between them, not either number alone, is your actual exposure. The one-day weaponization window on CVE-2026-55040 isn&#8217;t an outlier. It&#8217;s what the DBIR data predicted would start happening more often.</p><h3><span>The Architectural Question</span></h3><p>The tactical response to all of this is &#8220;patch faster.&#8221; Patch faster. Also accept that faster patching alone is a losing race against a 55% year-over-year jump in exploitation speed, because the DBIR numbers say so directly. The more durable response is architectural. Stop building systems where authenticating a session once buys an attacker standing, durable access to everything that session can reach.</p><p>Kiteworks is one example of a platform built on the opposite premise from the start. Every request for content, human or machine, gets evaluated against policy individually through the Kiteworks Control Plane rather than inheriting trust from a session token, and the platform runs as a single-tenant <a href="http://kiteworks.com/platform/security/hardened-virtual-appliance">hardened virtual appliance</a> rather than a general-purpose collaboration surface retrofitted with security controls. That is not a claim that per-request policy enforcement makes any platform immune to every future vulnerability class; no honest vendor claims that. It is a description of which category of attack surface, forge a token once and walk around indefinitely, simply doesn&#8217;t exist in that model. Kiteworks&#8217; own <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">2026 Data Security and Compliance Risk: Annual Forecast Report</a> has tracked this exact tension between platform consolidation and governed, per-request access control as one of the year&#8217;s defining data security questions, and the SharePoint chain is a live illustration of why.</p><h3><span>Where to Spend the Next Two Weeks</span></h3><p>A checklist, because architecture arguments don&#8217;t patch servers on their own:</p><p><span>1. </span>Confirm CVE-2026-55040 and CVE-2026-63520 are patched on every on-premises SharePoint Server 2016, 2019, and Subscription Edition instance you run. SharePoint Online was not affected; don&#8217;t waste the week chasing the wrong environment.</p><p><span>2. </span>Rotate IIS machine keys and any <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> the server could reach, regardless of patch status. Unit 42 said it about the 2025 campaign and it&#8217;s true again now. The patch doesn&#8217;t undo what a stolen key already did.</p><p><span>3. </span>Pull authentication and Business Connectivity Services logs for the window between disclosure and patch, and treat any gap in that logging as its own finding, not a footnote.</p><p><span>4. </span>Ask your architecture team, in writing, which of your platforms grant durable session trust versus which check every request against policy. Get an actual list. Most teams have never written it down.</p><p><span>5. </span>Put time-to-patch next to time-to-exploit on the next board slide. The DBIR just told you the gap between them is the number that matters, not either one in isolation.</p><p>Two bugs, disclosed weeks apart, by two people who&#8217;d never met, became one exploit chain because attackers do the connecting work your patch tracker isn&#8217;t built to do.</p>]]></content:encoded></item><item><title><![CDATA[73% of Companies Can't Restrict What Their AI Agents Do]]></title><description><![CDATA[Meta's approved AI agent didn't break a single rule. That's exactly the governance failure nobody built controls for.]]></description><link>https://kiteworks.substack.com/p/73-of-companies-cant-restrict-what</link><guid isPermaLink="false">https://kiteworks.substack.com/p/73-of-companies-cant-restrict-what</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Thu, 10 Sep 2026 15:02:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!kpF6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kpF6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kpF6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!kpF6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!kpF6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!kpF6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kpF6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bc054567-c322-43ed-ba0e-81685c0db144_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:575980,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/214967795?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kpF6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!kpF6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!kpF6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!kpF6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbc054567-c322-43ed-ba0e-81685c0db144_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On a Tuesday in March 2026, a Meta employee posted a technical question to an internal forum. An engineer ran it through an approved internal AI agent to draft an analysis. The agent posted that analysis publicly, on its own, without asking anyone first. According to <a href="https://thehackernews.com/2026/08/why-shady-ai-is-securitys-next-big.html"><span>The Hacker News&#8217;s coverage</span></a> of the incident, the employee then acted on the agent&#8217;s advice, and for more than two hours, sensitive company and user data sat exposed to engineers who had no business seeing it. Meta logged it as a Sev 1.</p><p>Here is what did not happen. Nobody used an unsanctioned tool. Nobody went around a policy. The agent was approved, deployed, and sanctioned by the same process that governs every other piece of Meta&#8217;s internal tooling. That is not the exception to the <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> story security teams have been telling for two years. It is the story they have not been telling at all.</p><h3><strong>The Vocabulary Security Got Wrong</strong></h3><p>Security has spent two years building a vocabulary around unauthorized AI use. <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">Shadow AI</a> is an employee routing company data through an unapproved chatbot. The fix is visibility and blocking. It is a real problem, and it is the wrong problem for what happened at Meta.</p><p>The Hacker News piece, contributed by workflow-automation vendor Tines, draws the distinction the industry needs. Shadow AI is unapproved tool use. What happened at Meta was an employee using an approved tool in a way nobody approved. Call it shady AI if you want a name for it. The tool passed procurement. The tool passed security review. Nobody built a fence around what the tool could do once it was inside the building.</p><p>Security teams are already being asked to own this problem. The SANS Institute&#8217;s <a href="https://www.sans.org/press/announcements/ai-use-cybersecurity-jumped-from-50-to-78-year-ai-related-failures-rose-sharply-too-new-sans-institute-survey-reveals-governance-gap"><span>July 2026 AI survey</span></a> of 536 cybersecurity and IT practitioners found that 76% of security teams now hold a formal governance role for enterprise AI, up from 68% a year earlier. But governance ownership and governance capability are two different assets. You can own a function on an org chart and still lack the technical control to exercise it. That is the gap the Meta incident just exposed in public, one most CISOs are carrying without their boards knowing it.</p><h3><strong>The Data Says the Agents Are Already Off the Leash</strong></h3><p>Purpose binding is the technical control that would have stopped Meta&#8217;s agent cold, a rule that restricts an AI agent to its authorized task and its authorized data scope, enforced in the infrastructure rather than written into a policy document. <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/"><span>Kiteworks Data Security and Compliance Risk: 2026 Annual Survey Report</span></a>, a survey of 459 security and compliance leaders published in July 2026, found that 73% of organizations have no purpose binding deployed on their AI agents. Not weak purpose binding. None.</p><p>That absence shows up as a reported incident, not a hypothetical. Among organizations in the same survey running AI in production, 13% reported an AI agent exceeding its authorized scope in the past 12 months, and 19% reported discovering <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> usage as a distinct incident type. Neither figure describes Meta by name. Both describe the exact failure mode Meta demonstrated for the entire industry to read about.</p><p>The instinct to answer this with a ban is understandable, and it is also over. Cisco&#8217;s <a href="https://www.cisco.com/c/en/us/about/trust-center/data-privacy-benchmark-study.html"><span>2026 Data and Privacy Benchmark Study</span></a> found that outright organizational bans on generative AI tool usage fell from 28% of organizations in 2025 to 7% in 2026, a 21-point drop in a single year, with no corresponding rise in the technical controls that would need to replace a ban. Organizations are not choosing to govern AI agents more precisely. They are choosing to stop blocking them and have not yet built what comes next.</p><h3><strong>Why the Math Got Worse</strong></h3><p>An AI assistant that started as a document summarizer six months ago may now search internal knowledge bases, call business applications, and take actions on an employee&#8217;s behalf, all without a second procurement review. The Hacker News piece names this pattern plainly. The tool has not changed from a governance perspective, but what an employee can do with it has, and that expansion has outrun the annual or semiannual review cycle most enterprises apply to approved software.</p><p>Speed is the compounding variable, and it cuts in both directions. CrowdStrike&#8217;s <a href="https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/"><span>2026 Global Threat Report</span></a> documented AI-enabled lateral movement happening in as little as 27 seconds after initial access. That statistic gets cited constantly as an external-attacker problem. It applies with equal force to an internal AI agent operating inside its own permission set. An agent does not need ninety minutes to decide whether posting an analysis publicly is wise. It decides in the time it takes to generate the next output. A governance model built around quarterly access reviews and annual tool audits is not slow relative to an external adversary. It is slow relative to the tools your own employees already have standing permission to use.</p><h3><strong>The Architectural Question</strong></h3><p>None of this is an argument for more training or a longer acceptable use policy. SANS found that 76% of security teams now own AI governance. Nobody has found that 76% can technically enforce it, and training a workforce on a policy the infrastructure does not enforce produces documented awareness of a violation employees remain fully able to commit.</p><p>The alternative is building the restriction into the environment where the AI-assisted work happens, so the governed path is also the easiest one to follow. That means purpose binding and role- and <a href="http://kiteworks.com/risk-compliance-glossary/attribute-based-access-control/">attribute-based access controls</a> enforced at the point an AI agent or a human requests sensitive data, not after the fact, backed by an <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> detailed enough to reconstruct what was accessed, by which identity, and under what authorization. It would not have stopped Meta&#8217;s agent from drafting a flawed analysis. It would have stopped that analysis from reaching engineers who had no authorization to see the underlying data, because the posting action itself would have required a permission the agent did not hold. That is a narrower claim than &#8220;solves AI risk,&#8221; and it is the honest one. Governance built into the access layer controls what data an agent can reach and expose. It does not control whether the agent makes a good decision with the access it is given.</p><h3><strong>Where Purpose Binding Needs to Live This Quarter</strong></h3><p>The Meta incident is a preview, not an outlier. Here is what to do with it before your own approved agent produces the next one:</p><p><span>&#8226; </span>Inventory every AI agent with write or publish access to internal or external-facing systems, not just the tools with read access to sensitive data. Meta&#8217;s agent could publish. That is a different risk than an agent that can only summarize.</p><p><span>&#8226; </span>Ask your AI vendors to demonstrate purpose binding live, in the product, rather than describe it in a data sheet. Seventy-three percent of organizations in the Kiteworks 2026 Annual Survey Report have none deployed. Confirm you are not one of them.</p><p><span>&#8226; </span>Name a single accountable owner for AI agent governance who is not the same person who approved the underlying tool procurement. Approval and containment are different jobs.</p><p><span>&#8226; </span>Confirm you can produce a complete record of what a given AI agent accessed, and what it did with that access, within one business day. Most organizations in the same survey cannot.</p><p><span>&#8226; </span>Report the gap to your board as a compliance exposure, in the language of audit and liability, before an examiner or a plaintiff&#8217;s attorney asks the question first.</p><p>The next Sev 1 will not come from a tool nobody approved. It will come from one everybody already signed off on.</p>]]></content:encoded></item><item><title><![CDATA[The Pentagon Paused CMMC. Confidence in the Numbers Kept Falling.]]></title><description><![CDATA[Self-reported compliance scores just hit a multi-year high. Confidence in those scores just hit a multi-year low.]]></description><link>https://kiteworks.substack.com/p/the-pentagon-paused-cmmc-confidence</link><guid isPermaLink="false">https://kiteworks.substack.com/p/the-pentagon-paused-cmmc-confidence</guid><dc:creator><![CDATA[Danielle Barbour]]></dc:creator><pubDate>Wed, 09 Sep 2026 23:45:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!kShp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kShp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kShp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!kShp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!kShp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!kShp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kShp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:445409,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/214966309?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kShp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!kShp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!kShp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!kShp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F544b7ef2-47d9-4c9a-8350-48df68cc503e_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span>On September 3, 2026, the Pentagon signed Revision 3 of its </span><a href="http://kiteworks.com/risk-compliance-glossary/dfars/"><span>DFARS</span></a><span> class deviation, locking in a suspension of mandatory third-party </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc/"><span>CMMC</span></a><span> assessment through November 2028. Self-attestation now carries the weight of law for two more years. CyberSheath&#8217;s </span><a href="https://cybersheath.com/resources/downloads/2026-state-of-the-defense-industrial-base-protecting-the-mission/">2026 State of the Defense Industrial Base report</a><span>, an annual survey of 302 US defense contractors fielded that same year, found something that should worry anyone celebrating the extra runway. Contractor confidence in the accuracy of their own compliance scores just hit its lowest recorded level, even as the scores themselves hit a multi-year high.</span></p><p><span>Read that again. Scores are up. Confidence in them is down.</span></p><p><span>That is not the story most of the trade press is telling about the Cybersecurity Maturity Model Certification program right now. The story everyone is telling is that the Pentagon suspended Phase 2 assessments again in September, pushed the real deadline out to November 2028, and the defense industrial base can finally exhale. The confidence data says otherwise. What was supposed to catch the gap between what a company claims and what is actually true was never the paperwork itself. It was independent verification, and that is exactly the piece that just got suspended. If anything, the gap got more dangerous, because now almost nobody outside the company is checking it.</span></p><h3><strong><span>What Revision 3 Actually Suspended</span></strong></h3><p><span>DARS Class Deviation 2026-O0025, Revision 3, signed September 3, 2026, writes a new automatic trigger date directly into the </span><a href="http://kiteworks.com/risk-compliance-glossary/dfars/"><span>DFARS</span></a><span> text. November 10, 2028, two years later than the market had built toward. CMMC Level 1 and Level 2 can now be satisfied through self-assessment instead of a </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc-third-party-assessor-organization-c3pao/"><span>C3PAO</span></a><span> or government review. Contracting officers are stripping the mandatory assessment requirement out of active solicitations.</span></p><p><span>What the revision does not touch is DFARS 252.204-7012 or the underlying </span><a href="http://kiteworks.com/risk-compliance-glossary/protect-cui-with-nist-800-171-compliance/"><span>NIST SP 800-171</span></a><span> control set, all 110 of them, which remain fully in force. A self-attested Conditional </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc/"><span>CMMC</span></a><span> status is valid for 180 days before it must convert to Final status, itself valid for three years. The Defense Contract Management Agency retains full authority to run a Medium or High assessment on any covered system at any time, self-assessed or not, and that result overrides whatever was previously posted. A contractor gets 14 business days to rebut an adverse finding before it becomes the record the government relies on for the next award. None of those clocks paused. Only the independent check on whether a contractor&#8217;s own number is true did.</span></p><h3><strong><span>The Confidence Theater Underneath the Numbers</span></strong></h3><p><span>Here&#8217;s where it gets uncomfortable. </span><a href="https://www.kiteworks.com/cmmc-compliance/cmmc-2-0-dib-compliance-report/">Kiteworks&#8217; State of CMMC 2.0 Preparedness in the DIB report</a><span>, surveying 273 defense contractors after the suspension took effect, found 96% confident their SPRS score would hold up under scrutiny. Only 29% could produce both a current submission and a platform capable of proving it. Seventy-one percent of a market that says it&#8217;s fine cannot show its work.</span></p><p><span>That is not compliance. That is confidence theater.</span></p><p><span>That gap is not unique to Kiteworks&#8217; sample. It is the same disconnect CyberSheath found industry-wide. Confidence in score accuracy fell from 89% to 65% in a single year, even as the mean self-reported score climbed to its highest level in the five years CyberSheath has tracked it. Two different surveys, two different samples, the same shape of gap.</span></p><h3><strong><span>Why the Suspension Makes the Math Worse, Not Better</span></strong></h3><p><span>Here&#8217;s the whole game: the suspension didn&#8217;t lower the risk. It removed the only mechanism that was catching the gap between claim and reality before the government did.</span></p><p><span>There is a remote legal wrinkle here worth a sentence and nothing more. A </span><a href="https://www.lawfaremedia.org/article/rulemaking-by-memo--why-cmmc-suspension-deserves-review">Lawfare analysis by Michael McLaughlin and Harvey Rishikof</a><span> questions whether the Pentagon had the authority to suspend the program this way. It is a long shot, not a plan. The extension just got extended again, and self-attestation carries the full weight of law for two more years with nobody double-checking it either way.</span></p><p><span>Meanwhile the enforcement side of the ledger is not slowing down to match the market&#8217;s mood. The Department of Justice </span><a href="https://www.justice.gov/opa/pr/false-claims-act-settlements-and-judgments-exceed-68b-fiscal-year-2025">recovered a record $6.8 billion in False Claims Act settlements and judgments in fiscal year 2025</a><span>, and cybersecurity certification is one of its most active enforcement lanes. A regulator relaxed the check. A prosecutor did not relax the standard.</span></p><h3><strong><span>Stop Waiting for the Audit. Start Building the Evidence.</span></strong></h3><p><span>The tactical response to a paused assessment is to wait for it to resume, or scramble when a court or a new administration reinstates it. That is exactly backward. The contractors who come out ahead over the next two years are the ones treating evidence generation as infrastructure, not as a project that starts when the assessor calls.</span></p><p><span>That is the architectural shift worth naming. Platforms like Kiteworks, built with single-tenant isolation and </span><a href="http://kiteworks.com/risk-compliance-glossary/fips/"><span>FIPS 140-3</span></a><span> validated </span><a href="http://kiteworks.com/secure-file-sharing/public-vs-private-key-encryption/"><span>encryption</span></a><span>, produce an audit-ready trail as a byproduct of normal operation, the kind of evidence a contracting officer, a DCMA assessor, or a False Claims Act relator can all be handed without three weeks of scrambling to reconstruct it. That is the difference between a company that can prove its SPRS score and the 71% that currently cannot.</span></p><p><span>What to fix before the assessors come back:</span></p><p><strong><span>1. </span></strong><span>Pull your own SPRS submission this week and check it against what you can actually document, not what you remember attesting to.</span></p><p><strong><span>2. </span></strong><span>Map every subcontractor touching </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc-cui-and-what-it-means/"><span>controlled unclassified information</span></a><span>. </span><a href="http://kiteworks.com/risk-compliance-glossary/dfars/"><span>DFARS</span></a><span> 252.204-7012 flows down through the whole chain, not just the name on the prime contract.</span></p><p><strong><span>3. </span></strong><span>Track the 180-day and three-year clocks on any Conditional status personally. Nobody in Washington is tracking them for you anymore.</span></p><p><strong><span>4. </span></strong><span>Build toward continuous, automatic evidence generation instead of a spreadsheet somebody updates before an audit that might not come for two years, or might come next month if a court intervenes.</span></p><p><strong><span>5. </span></strong><span>Do not wait on a court to settle this. Whoever spends the window building a defensible evidence trail gets a real edge over whoever spends it waiting.</span></p><p><span>The assessment got suspended. The proof you owe the government did not.</span></p>]]></content:encoded></item><item><title><![CDATA[Level 2 Is Already Priced Into Every Defense Bid.]]></title><description><![CDATA[The suspension paused the assessments, not the market. Your position in the supply chain now decides who you lose to.]]></description><link>https://kiteworks.substack.com/p/level-2-is-already-priced-into-every</link><guid isPermaLink="false">https://kiteworks.substack.com/p/level-2-is-already-priced-into-every</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Wed, 09 Sep 2026 15:01:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hTCl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hTCl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hTCl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!hTCl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!hTCl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!hTCl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hTCl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:496152,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/214763396?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hTCl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!hTCl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!hTCl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!hTCl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e038723-a877-4e82-9806-4a8d0dc293be_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A Tier 2 machining subcontractor spent the second half of July watching two solicitations it had counted on get away. Not because its price moved. Not because its past performance slipped. Because a prime further up the chain wanted proof of Level 2 posture before it would let anyone touch controlled unclassified information, and the subcontractor could not put that proof on the table fast enough. The Department of War suspended third-party <a href="http://kiteworks.com/platform/compliance/cmmc-compliance/">CMMC 2.0</a> assessments on July 13, 2026. To this shop, the suspension changed nothing that mattered.</p><p>That is the part the headlines missed. When the assessment machinery paused, a lot of the market read it as a reprieve. The data says the opposite. Buyers did not stop pricing Level 2 into their decisions. They just stopped waiting for a certificate to do it -- and the firms that already carry the requirement in their bones are using the pause to take share from the firms that do not.</p><p>We surveyed 273 <a href="http://kiteworks.com/risk-compliance-glossary/defense-industrial-base/">Defense Industrial Base</a> organizations between July 17 and July 31, 2026, all confirmed to do DoW business under an active <a href="http://kiteworks.com/platform/compliance/cmmc-compliance/">CMMC 2.0</a> requirement -- one of the first clean reads of how the base behaved once the assessments stopped. The market story inside the <em>State of CMMC 2.0 in the DIB</em> report is blunt.</p><h3><span>The Suspension Moved the Deadline, Not the Requirement</span></h3><p><span>Start with what buyers are doing, not what the policy says. Fifty-five percent of respondents are now bidding on solicitations they previously would have avoided over Level 2 concerns. Read that twice. A majority of the base is chasing work it used to walk away from, because the enforcement checkpoint everyone was bracing for slipped.</span></p><p><span>That is not caution. That is a scramble for open ground.</span></p><p><span>At the same time, 52 percent have withdrawn from a bid, and 38 percent have already lost or been disqualified over Level 2. Those are not the numbers of a market waiting for clarity. This market is already sorting winners from losers on posture, with or without an assessor in the room. The certificate was never what buyers wanted. Confidence in the supplier was, and they are buying it from whoever can demonstrate it today.</span></p><p><span>The suspension paused an assessment step. It did not pause </span><a href="http://kiteworks.com/risk-compliance-glossary/dfars/"><span>DFARS</span></a><span> 252.204-7012, </span><a href="http://kiteworks.com/risk-compliance-glossary/protect-cui-with-nist-800-171-compliance/"><span>NIST SP 800-171</span></a><span>, the Phase 1 self-assessment, or the SPRS submission. Every one of those obligations still stands, and so does the </span><a href="http://kiteworks.com/risk-compliance-glossary/false-claims-act/"><span>False Claims Act</span></a><span> on the score you attest to. The requirement did not leave the building. It just stopped announcing itself at the door.</span></p><h3><span>The Loss Rate Has a Tier Number On It</span></h3><p><span>Here is the finding that should reorganize how you think about your exposure: the pain is not spread evenly across the base. It concentrates by position.</span></p><p><span>Tier 2 and deeper subcontractors are losing bids over Level 2 at 55 percent -- nearly double the 31 percent rate primes report. The further you sit from the contracting officer, the more often the requirement costs you the work. That gap is structural. Obligations cascade down the chain; bargaining power, budget, and compliance staff do not cascade with them. The tier that inherits the requirement is the tier least equipped to prove it, and the bid outcomes show exactly that.</span></p><p><span>The insulation runs the other direction too. Aerospace and Defense Manufacturing -- the segment that has lived inside </span><a href="http://kiteworks.com/risk-compliance-glossary/risk-compliance-glossary-itar/"><span>ITAR</span></a><span> and defense contracting rigor for decades -- posts the lowest loss rate in the survey at 16 percent. These firms priced Level 2 into their operations years ago. When the assessment step vanished, their bidding did not change -- their readiness never depended on it.</span></p><p><span>So the suspension did not create a level field. It exposed the one that was already tilted.</span></p><h3><span>Readiness Runs Along the Same Fault Line</span></h3><p><span>The bid outcomes are not random. They track a readiness gap you can measure.</span></p><p><span>We scored every respondent on a CMMC Suspension Readiness Index, combining current compliance maturity with governance actions taken since July 13. The full base averages 60.0. Break it out by role and the pattern reappears. Firms that operate as both prime and sub score 64.7. Pure primes come in at 61.6. Tier 1 subs drop to 52.1, and Tier 2-plus subs sit at 52.2 -- a full twelve points under the dual-role firms winning the work.</span></p><p><span>The organizations losing bids are the same organizations carrying the weakest readiness. Position, readiness, and outcome line up on one axis.</span></p><p><span>They also know it. Flow-down is the anxiety that gives the pattern away. Concern about cascading Level 2 obligations runs at 86 percent across the base, but it climbs to 92 percent among Tier 1 subcontractors -- the firms staring directly up at requirements their primes will pass down whether the assessments resume or not. They feel it most sharply because they hold the least control over it.</span></p><h3><span>Why Position, Not the Pause, Decides Exposure</span></h3><p><span>The strategic picture is clear. Level 2 is not a future compliance event the base is waiting on. It is a present-tense market filter that buyers are already applying. The World Economic Forum&#8217;s </span><em><span>Global Cybersecurity Outlook 2026</span></em><span> found 65 percent of large organizations now rank third-party and </span><a href="http://kiteworks.com/risk-compliance-glossary/supply-chain-risk-management/"><span>supply-chain risk</span></a><span> as their greatest challenge to cyber resilience, up from 54 percent a year earlier. Primes are not softening their demands during the pause. They are hardening them, because the risk they are managing did not pause either.</span></p><p><span>That reframes the response. If exposure tracks position in the chain, buying another point tool or filing another self-attestation does not move you. What moves you is demonstrating governed handling of </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc-cui-and-what-it-means/"><span>controlled unclassified information</span></a><span> on demand -- the audit-ready evidence a prime accepts in place of a certificate that no longer exists. Platforms built on that premise matter here for a structural reason, not a marketing one: a single-tenant system that keeps </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc-cui-and-what-it-means/"><span>CUI</span></a><span> inside one governed boundary and produces its own </span><a href="http://kiteworks.com/regulatory-compliance/audit-log/"><span>audit trail</span></a><span> is </span><a href="http://kiteworks.com/risk-compliance-glossary/fedramp/"><span>FedRAMP High In Process</span></a><span> and FedRAMP Moderate Authorized, which is the kind of proof a nervous prime will take today. The Kiteworks Control Plane is one example of that architecture. The point is not the product. The point is that proof-on-demand is now a bidding asset, and the firms that have it are converting it into contracts.</span></p><h3><span>What This Means Monday Morning</span></h3><p><span>The suspension bought time. It did not buy relief. Here is where a competent bid team spends the week.</span></p><p><span>1. </span><strong><span>Map your loss rate by tier, not in aggregate.</span></strong><span> If you sit at Tier 2 or deeper, benchmark against the 55 percent loss rate, not the 31 percent prime figure -- and put that tier-specific number in front of your board.</span></p><p><span>2. </span><strong><span>Treat every open solicitation as a posture test.</span></strong><span> With 55 percent of the base now bidding on work they used to avoid, the field you compete against just got more crowded and more prepared. Assume your prime is screening on demonstrable readiness.</span></p><p><span>3. </span><strong><span>Build the evidence package a prime can accept without an assessor.</span></strong><span> A current SPRS submission plus audit-ready handling of </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc-cui-and-what-it-means/"><span>CUI</span></a><span> is the substitute for the certificate the market is missing.</span></p><p><span>4. </span><strong><span>Pressure-test your flow-down before your prime does.</span></strong><span> Ninety-two percent of Tier 1 subs are already worried about it. If your subcontractors cannot show posture, their gap becomes your disqualification.</span></p><p><span>The assessors will come back. Fifty-eight percent of the base expects Phase II to return in modified form. But the bids are being decided now, on posture the market can see -- and the firms treating the pause as a finish line are handing share to the firms treating it as a head start.</span></p><p><span>Read the full analysis in the </span><em><a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-cmmc-2-0-dib-readiness.pdf"><span>State of CMMC 2.0 in the DIB</span></a></em><a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-cmmc-2-0-dib-readiness.pdf"><span> report</span></a><span>.</span></p>]]></content:encoded></item><item><title><![CDATA[Europe’s DIB Is 44% Exposed. It Stays 94% Confident.]]></title><description><![CDATA[CMMC obligations flow down US defense contracts into European supply chains, and Europe is entering that regime carrying the least-current self-attestations in the study.]]></description><link>https://kiteworks.substack.com/p/europes-dib-is-44-exposed-it-stays</link><guid isPermaLink="false">https://kiteworks.substack.com/p/europes-dib-is-44-exposed-it-stays</guid><dc:creator><![CDATA[Marc ten Eikelder]]></dc:creator><pubDate>Tue, 08 Sep 2026 17:15:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!V5Ec!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V5Ec!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V5Ec!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!V5Ec!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!V5Ec!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!V5Ec!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V5Ec!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:406089,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/214760169?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V5Ec!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!V5Ec!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!V5Ec!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!V5Ec!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F217dbab0-a55f-4429-9f8f-cf2f5d2b7271_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On July 13, 2026, the US Department of War suspended third-party assessments under Phase II of <a href="http://kiteworks.com/platform/compliance/cmmc-compliance/">CMMC 2.0</a>. From where I sit in the EMEA market, a lot of people read that as a reprieve. It was not. The suspension paused who checks the work. It paused nothing about the work itself.</p><p>That gap between what was suspended and what was heard is where European defense suppliers are most exposed, and least aware of it.</p><p>Think about the shape of a typical US defense <a href="http://kiteworks.com/risk-compliance-glossary/supply-chain-risk-management/">supply chain</a> from this side of the Atlantic. A French avionics software house, a Dutch logistics integrator, an Italian components maker &#8211; each one sitting several tiers down, each carrying a CMMC requirement it inherited from a prime it may never speak to directly. A new study of 273 DIB organizations that do business with the DoW and carry an active <a href="http://kiteworks.com/platform/compliance/cmmc-compliance/">CMMC 2.0</a> requirement included 104 European entities. That is 38% of the sample. It is also the weakest posture in the report.</p><h3><span>The Numbers Europe Would Rather Not Read</span></h3><p><span>The study scores readiness on a combined index that multiplies current compliance against active governance behavior since the suspension. The full sample lands at 60.0. North America lands at 64.7. Europe lands at 53.9 &#8211; an eleven-point gap, the largest regional divergence in the data.</span></p><p><span>Break that open and it gets sharper. Of the four readiness quadrants, Europe puts 44% of its organizations in the Exposed category, against 31% for the full sample. Only 15% of European entities reach Audit-Ready, against 23% overall. So Europe carries more organizations at the bottom and fewer at the top than any other region measured.</span></p><p><span>Here is the one that should stop a compliance lead cold. Just 43% of European organizations have a current SPRS submission. In North America that figure is 70%. Across the full sample it is 59%. The self-attested score sitting in the US government&#8217;s Supplier Performance Risk System is, for most European suppliers, out of date.</span></p><p><span>And yet 94% of them remain confident that score would hold up under review.</span></p><h3><span>Flow-Down Doesn&#8217;t Care Where You Are Registered</span></h3><p><span>The reason a Rotterdam or Toulouse supplier carries this obligation at all is flow-down. When a US prime accepts a DoW contract with </span><a href="http://kiteworks.com/risk-compliance-glossary/dfars/"><span>DFARS</span></a><span> clause 252.204-7012, that clause travels down every tier of the chain. </span><a href="http://kiteworks.com/risk-compliance-glossary/protect-cui-with-nist-800-171-compliance/"><span>NIST SP 800-171</span></a><span> controls travel with it. So does the Phase 1 self-assessment. So does the SPRS submission. None of that paused on July 13.</span></p><p><span>Neither did the enforcement mechanism. The </span><a href="http://kiteworks.com/risk-compliance-glossary/false-claims-act/"><span>False Claims Act</span></a><span> still applies to the self-attested score, and the DOJ&#8217;s Civil Cyber-Fraud Initiative is the vehicle for pursuing it. A stale or unsupported score is not a paperwork problem. It is a representation made to the US government, and being registered in Milan rather than Maryland does not change that.</span></p><p><span>The suppliers themselves feel the pressure. Across the full sample, 86% named flow-down as a concern, rising to 92% among tier-one subcontractors. What worries me is the knowledge gap underneath the confidence. In Europe, 55% of respondents did not know the Phase 1 self-assessment obligation continues during the suspension, above the 48% full-sample figure. You cannot maintain an obligation you believe has been paused.</span></p><h3><span>The Pattern Runs Wider Than CMMC</span></h3><p><span>CMMC did not appear out of nowhere. It exists because third-party risk has become the dominant way defense data gets exposed, and the wider evidence backs that up.</span></p><p><span>The </span><a href="https://www.verizon.com/business/resources/reports/dbir/"><span>Verizon 2026 Data Breach Investigations Report</span></a><span> found that breaches involving a third party grew 60% year over year, reaching 48% of all breaches analyzed. In Public Administration specifically, a third party was present in 36% of incidents. The </span><a href="https://www.weforum.org/publications/global-cybersecurity-outlook-2026/"><span>World Economic Forum&#8217;s Global Cybersecurity Outlook 2026</span></a><span> reports that 65% of large organizations now rank third-party and supply-chain risk as their greatest challenge to cyber resilience, up from 54% a year earlier.</span></p><p><span>The cost side matches. The </span><a href="https://www.ibm.com/reports/data-breach"><span>IBM Cost of a Data Breach Report 2026</span></a><span> puts supply-chain compromise as the single largest cost-increasing factor, adding $227,250 to the average breach, with regulatory noncompliance close behind at $201,112. CMMC is the DoW&#8217;s structural answer to exactly this problem. A European supplier that treats it as a distant US formality has misread the direction of the whole market.</span></p><h3><span>Why Confidence Is the Wrong Instrument</span></h3><p><span>Confidence, in this data, is not tracking readiness. It is decoupled from it.</span></p><p><span>Look inside Europe by country, where the sample supports it. In France, the largest European cohort at 58 organizations, 43% hold a current SPRS submission while 88% report concern about </span><a href="http://kiteworks.com/risk-compliance-glossary/false-claims-act/"><span>False Claims Act</span></a><span> exposure. That is a workforce that senses the legal risk clearly and has not yet closed the evidence gap underneath it. The Netherlands, at 22 organizations, sits at 50% current submissions and 86% FCA concern. The pattern holds: the worry is real, the paperwork is not caught up.</span></p><p><span>Across Europe as a whole, 82% report FCA concern and 83% have engaged legal or compliance review since the suspension. Those are healthy instincts. But legal review does not produce a current SPRS score, and it does not generate the </span><a href="http://kiteworks.com/regulatory-compliance/audit-log/"><span>audit trail</span></a><span> that a review would demand. When the full study asked what would most increase confidence, the top answer was an audit trail at 47%, well ahead of legal review at 11%. The suppliers know what they are missing. Most have not yet built it.</span></p><h3><span>The Architectural Question</span></h3><p><span>If the gap is evidence, then the fix is not another policy memo. It is infrastructure that produces defensible proof of how sensitive data moves and who touched it, generated as a byproduct of normal operations rather than assembled by hand before an assessment.</span></p><p><span>This is the architectural bar to hold any platform to. Kiteworks, as one example, runs a single-tenant Control Plane that generates audit-ready evidence across the channels regulated data moves through &#8211; and the platform is </span><a href="http://kiteworks.com/risk-compliance-glossary/fedramp/"><span>FedRAMP High In Process</span></a><span> and FedRAMP Moderate Authorized, which matters when the obligation you inherited originates from the US federal government. The point is not the vendor. The point is that a stale self-attestation and a folder of screenshots is not evidence, and a European supplier defending a flow-down obligation needs the real thing.</span></p><h3><span>What This Means Monday Morning</span></h3><p><span>If you sit inside a US defense </span><a href="http://kiteworks.com/risk-compliance-glossary/supply-chain-risk-management/"><span>supply chain</span></a><span> from Europe, this week:</span></p><p><span>1. Pull your actual SPRS submission date. If it predates your last material system change, it is stale, and 43% of your European peers are in the same position.</span></p><p><span>2. Confirm in writing that your Phase 1 self-assessment obligation is live. It did not pause on July 13, whatever the suspension headlines suggested.</span></p><p><span>3. Map every </span><a href="http://kiteworks.com/risk-compliance-glossary/dfars/"><span>DFARS</span></a><span> 252.204-7012 flow-down clause in your active contracts. You cannot maintain an obligation you have not located.</span></p><p><span>4. Ask one question of your current controls: if the DOJ requested evidence tomorrow, could you produce an </span><a href="http://kiteworks.com/regulatory-compliance/audit-log/"><span>audit trail</span></a><span>, or only assurances?</span></p><p><span>5. Separate the legal review from the evidence work. One tells you the risk. Only the other reduces it.</span></p><p><span>The suspension did not lower the bar for European suppliers. It removed the assessor who was going to tell you where you stood &#8211; and left the liability exactly where it was.</span></p><p><span>Kiteworks has published a European Executive Summary of the full findings for exactly this audience. Read it </span><a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-brief-cmmc-2-0-dib-europe-executive-summary.pdf"><span>here</span></a><span>.</span></p><p><em><span>Marc ten Eikelder is Senior Director Marketing EMEA at Kiteworks.</span></em></p>]]></content:encoded></item><item><title><![CDATA[Microsoft Patched Copilot's Bug. It Didn't Patch Your Blind Spot.]]></title><description><![CDATA[CoSnitch is a fixed vulnerability. The personal AI accounts quietly touching your company's mail, calendar, and files are not.]]></description><link>https://kiteworks.substack.com/p/microsoft-patched-copilots-bug-it</link><guid isPermaLink="false">https://kiteworks.substack.com/p/microsoft-patched-copilots-bug-it</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Fri, 04 Sep 2026 15:02:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!o0XL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o0XL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o0XL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp 424w, https://substackcdn.com/image/fetch/$s_!o0XL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp 848w, https://substackcdn.com/image/fetch/$s_!o0XL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp 1272w, https://substackcdn.com/image/fetch/$s_!o0XL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o0XL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/edfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:46978,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/214026952?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o0XL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp 424w, https://substackcdn.com/image/fetch/$s_!o0XL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp 848w, https://substackcdn.com/image/fetch/$s_!o0XL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp 1272w, https://substackcdn.com/image/fetch/$s_!o0XL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fedfeb5f9-de38-4e2c-9265-bffad46c798c_720x480.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On August 18, 2026, Microsoft shipped a fix for three vulnerabilities in Copilot Personal that Varonis Threat Labs named CoSnitch, tracked as <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24301">CVE-2026-24301</a>. A crafted link could make Copilot run an attacker&#8217;s prompt the instant the page loaded, no click required beyond opening it, and pull mail, calendar, Google Drive metadata, and chat history out through a webhook that looked, to every network monitor watching, exactly like Copilot summarizing a web page. Varonis found no evidence anyone exploited it. Good.</p><p>Now forget the patch. That&#8217;s not the story. Here is the story: this is a <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> evidence problem, not a Microsoft patch problem, and every enterprise treating it as the second thing is going to get surprised by the first.</p><h3><span>What CoSnitch Actually Proved</span></h3><p>Varonis got there by meta-hacking Copilot itself, asking it repeatedly why a prompt couldn&#8217;t run without a user gesture until the assistant&#8217;s own refusals named the bypass: an undocumented <span>autorun=1</span> parameter, paired with Copilot&#8217;s existing <span>q</span> parameter. Pair the two and the prompt executes on load, inside the victim&#8217;s authenticated session, with the same reach as anything the victim typed. It kept running even after the tab closed. <a href="https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html">The Hacker News covered the technical detail in full</a>: mail bodies, calendar attendees and locations, Drive file metadata, entire chat histories, all reachable, all exfiltrated through Copilot&#8217;s own built-in URL fetch.</p><p>Here&#8217;s the part that should bother a CISO more than the exploit chain: Varonis says the exfiltration request was indistinguishable at the network layer from ordinary Copilot summarization traffic. Not disguised. Not obfuscated. Identical. A second, related bug let a summarized web page write attacker instructions into Copilot&#8217;s persistent memory, where they survived password resets, session revocation, and device re-enrollment until someone manually found and deleted them. Standard <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a> neutralizes a compromised <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credential</a>. It does nothing to a poisoned memory that isn&#8217;t stored in the credential at all.</p><h3><span>This Is Not the First Time, and That&#8217;s the Pattern</span></h3><p>CoSnitch reused the same parameter-to-prompt entry point Varonis exploited months earlier in its <a href="https://thehackernews.com/2026/01/researchers-reveal-reprompt-attack.html">Reprompt research</a>. Two weeks before CoSnitch, the same team disclosed <a href="https://www.varonis.com/blog/rovoblast">RovoBlast</a>, a nearly identical one-click attack against Atlassian&#8217;s Rovo assistant. Researcher H&#229;kon M&#229;l&#248;y <a href="https://enklypesalt.com/posts/context-collapse-part1-poisoning-copilot-memory/">documented a related memory-poisoning path</a> in Microsoft 365 Copilot&#8217;s own summarization flow back in June. Johann Rehberger found memory writes and deletions through indirect <a href="http://kiteworks.com/risk-compliance-glossary/phishing-attacks/">prompt injection</a> in the same window.</p><p>Read that again: four disclosures, three vendors, one shape. URL parameters or summarized content seed a prompt into someone else&#8217;s authenticated AI session, and the resulting traffic is architecturally indistinguishable from the tool doing its job. This is not a Copilot problem. It is what happens when every AI assistant ships a URL-fetch capability and nobody outside the vendor is watching what that capability actually does with a user&#8217;s standing permissions.</p><h3><span>Why the Math Got Worse This Year</span></h3><p>None of this would matter much if personal AI accounts stayed personal. They don&#8217;t. A <a href="https://www.kolmogorovlaw.com/ai-notetakers-workplace-consent-survey">July 2026 survey</a> of 500 employed U.S. adults, commissioned by the litigation firm Kolmogorov Law and fielded through Pollfish, found that 38% had entered at least one type of work information into a personal AI account their employer doesn&#8217;t control, and 36.8% use AI tools for work at least partly through a personal account. Only 35.8% said their employer had a clear written policy on what could be shared with AI tools at all.</p><p><a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Kiteworks Data Security and Compliance Risk: 2026 Annual Survey Report</a>, fielded with 459 security and compliance leaders in Q2 2026, found the enterprise side of the same coin: 65% of organizations discovered employees using unapproved AI tools with organizational data in the past 12 months. Half could not produce a complete AI data access audit record within one business day. Sit with that number. Half.</p><p>CoSnitch existed for roughly eight months before it was patched. During that window, an unknown share of the 65% was connecting personal Copilot, or something like it, to mail and files the compliance program had no idea existed outside its walls. Nobody has to prove exploitation happened. The exposure existed whether or not anyone used it, and the <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> to rule it out doesn&#8217;t exist either.</p><h3><span>The Architectural Question Nobody Wants to Answer</span></h3><p>The tactical response to CoSnitch is patch and move on. That&#8217;s necessary and insufficient. The real question is not whether Copilot Personal had a bug. It&#8217;s whether your organization can answer, for any AI tool touching regulated data, what was accessed, by what authority, and whether that access is logged somewhere you control rather than somewhere the AI vendor controls.</p><p>Access-governance platforms can&#8217;t stop a client-side URL-parameter flaw from existing; that&#8217;s on the vendor writing the client. What a governance layer sitting in front of the content can do is make the request that follows subject to a policy check and an audit entry that exists independent of the AI vendor&#8217;s own logging: per-request authorization instead of standing access, and an <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> that is evidence-quality by design rather than reconstructed after an incident forces the question. That&#8217;s an architectural answer, not a product name. The point is that the answer has to live outside the AI client, because CoSnitch just proved the AI client&#8217;s own controls are not something you can audit, patch on your own timeline, or trust to log its own compromise.</p><h3><span>Where to Spend the Next Two Weeks</span></h3><p>Stop debating whether employees should use personal AI tools. That argument is already lost; 36.8% settled it without asking permission. Start doing the things that turn &#8220;we don&#8217;t know&#8221; into an answer:</p><p><span>1. </span>Inventory which personal AI accounts touch work mail, calendar, or file storage, this week, not next quarter.</p><p><span>2. </span>Write the AI-sharing policy your organization doesn&#8217;t have. Kolmogorov Law&#8217;s data says two in three of you don&#8217;t.</p><p><span>3. </span>Treat every AI assistant, sanctioned or not, as a privileged insider for access review and anomaly detection, not as a productivity tool that happens to read files.</p><p><span>4. </span>Ask your incident response team, specifically, whether their playbook accounts for AI memory as a persistence mechanism distinct from <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> and sessions. Most don&#8217;t.</p><p><span>5. </span>Build or buy an <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> for AI data access that exists independent of whatever the AI vendor logs, because the vendor&#8217;s log is the first thing you lose visibility into when the vendor is the thing that got played.</p><p>Microsoft closed CoSnitch in eight months and found no victims. The next one won&#8217;t announce itself, and the personal AI accounts already connected to your data won&#8217;t wait for a CVE number to be dangerous.</p>]]></content:encoded></item><item><title><![CDATA[An Average Would Have Said 77. The Honest Number Is 60.]]></title><description><![CDATA[Two indices, eight checkable facts each. Combine them by multiplying instead of averaging and the DIB&#8217;s readiness score drops 17 points. Here is why the lower number is the true one.]]></description><link>https://kiteworks.substack.com/p/an-average-would-have-said-77-the</link><guid isPermaLink="false">https://kiteworks.substack.com/p/an-average-would-have-said-77-the</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Thu, 03 Sep 2026 15:02:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Nh8T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Nh8T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Nh8T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!Nh8T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!Nh8T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!Nh8T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Nh8T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:524142,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/213924606?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Nh8T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!Nh8T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!Nh8T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!Nh8T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce4e49ad-8bfc-49a2-b4ff-11e87516a768_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When the Department of War suspended <a href="http://kiteworks.com/platform/compliance/cmmc-compliance/">CMMC 2.0</a> Phase II third-party assessments on July 13, 2026, the <a href="http://kiteworks.com/risk-compliance-glossary/defense-industrial-base/">Defense Industrial Base</a> did not go quiet. It moved. We surveyed 273 DIB organizations between July 17 and 31, all of them confirmed DoW contractors carrying an active CMMC 2.0 requirement, and 98% had taken at least one concrete action within days. Only 2% did nothing.</p><p>So the question was never whether the DIB was busy. The question was whether busy meant ready. To answer it, we had to build a number. And the first decision in building that number &#8211; multiply or average &#8211; determined everything that came after.</p><h3><span>Eight Facts, Not Eight Feelings</span></h3><p><span>We built two indices, and we built them out of facts a third party could check, not opinions a respondent could inflate.</span></p><p><span>The first is the CMMC Compliance Maturity Score, or CCMS: eight binary indicators of where an organization stands on current compliance obligations. Do you have a current SPRS submission or not. Are you on a </span><a href="http://kiteworks.com/risk-compliance-glossary/fedramp/"><span>FedRAMP</span></a><span>-authorized platform or not. Each indicator is a yes or a no, gathered across the sample, and the mean landed at 78.2 out of 100.</span></p><p><span>The second is the Suspension Governance Score, or SGS: eight binary indicators of what an organization has done since July 13 &#8211; legal review engaged, </span><a href="http://kiteworks.com/regulatory-compliance/audit-log/"><span>audit trail</span></a><span> work started, assessment continued voluntarily. Also checkable. Also a yes or a no. Mean of 74.9.</span></p><p><span>Two numbers in the high 70s. Read them side by side and the instinct is to relax. Both dimensions look healthy. A tidy summary would blend them and report a single readiness figure somewhere in the mid-to-high 70s, and the DIB would look like it had absorbed the shock and kept its footing.</span></p><p><span>That summary would be a lie of arithmetic.</span></p><h3><span>The Number You Get Depends on the Operator</span></h3><p><span>To combine current compliance with active governance into one readiness index, you have to pick an operator. Add the two and divide, and you get an average. Multiply them, and you get something else entirely.</span></p><p><span>We chose to multiply. The CMMC Suspension Readiness Index is CCMS times SGS-over-100, computed for each organization and then aggregated. Average the two dimensions and the DIB scores about 77. Multiply them and the mean CSRI is 60.0.</span></p><p><span>Seventeen points vanish between those two operators. Not because the data changed. Because the honest operator refuses to let one strong dimension paper over a weak one.</span></p><h3><span>Why Multiplication Tells the Truth</span></h3><p><span>An average is generous by design. It treats a shortfall on one dimension as something a surplus on the other can repay. Score 90 on compliance and 60 on governance, and the average hands you 75 &#8211; the 90 quietly covering for the 60. That trade is fine when the two things you are blending are interchangeable. Readiness is not that kind of quantity.</span></p><p><span>Current compliance and active governance are not substitutes. They are both necessary. An organization with an immaculate paper trail that has done nothing since the suspension is not ready. An organization frantically convening legal reviews on top of a stale SPRS submission is not ready either. Readiness requires both to be true at once, and multiplication is the operator that enforces &#8220;both.&#8221;</span></p><p><span>Multiply, and a low score on either dimension caps the result. A 90 and a 40 do not average to a comfortable 65; they multiply to 36. Strong compliance cannot mask thin activity. Busy activity cannot mask weak compliance. The ceiling on your readiness is set by your worse dimension, not rescued by your better one &#8211; which is exactly how a competent auditor, a contracting officer, or a plaintiff&#8217;s counsel under the </span><a href="http://kiteworks.com/risk-compliance-glossary/false-claims-act/"><span>False Claims Act</span></a><span> would read your posture. The math is only doing on paper what enforcement does in practice.</span></p><p><span>An average measures how good your best excuse sounds. A product measures whether your weakest link holds.</span></p><h3><span>The Quadrant the Average Would Have Hidden</span></h3><p><span>Multiplication does more than lower the headline number. It sorts the population in a way an average cannot.</span></p><p><span>Set a threshold of seven of eight indicators on each dimension &#8211; an index value of 87.5 &#8211; and cross the two axes, and the 273 organizations fall into four quadrants. Audit-Ready, strong on both, is 23% (63 organizations). Coasting, compliant but passive since the suspension, is 28% (76). Scrambling, active but not yet compliant, is 18% (49). And Exposed, weak on both, is the largest group at 31% (85 organizations).</span></p><p><span>The largest single quadrant is the one with nowhere to hide. An average would have folded those 85 organizations into a reassuring middle. The product pulls them out into the open.</span></p><p><span>One more number from the same cross-tab settles the matter. Only 2% &#8211; five organizations out of 273 &#8211; score a perfect eight of eight on both dimensions at once. Perfection on one dimension is common. Perfection on both is nearly extinct. Any scoring method that lets a single strong dimension carry the summary would have missed how rare genuine, two-sided readiness is.</span></p><h3><span>Mean 60.0, Median 65.6</span></h3><p><span>Look at the distribution and the shape confirms the choice. The mean CSRI is 60.0. The median is 65.6. When the mean sits below the median, the distribution is left-skewed: a tail of low scorers is dragging the average down while the typical organization sits higher.</span></p><p><span>That gap between 60.0 and 65.6 is not noise. It is the Exposed quadrant exerting gravity on the whole population. A method built on averages would have reported the central tendency and stopped. Multiplication plus the median tells you where the weight sits &#8211; and it sits in the tail, among the organizations least able to back their own attestations.</span></p><p><span>The metric is only as honest as the evidence under it. Our indicators are checkable at all &#8211; SPRS currency, platform authorization, audit-trail completeness &#8211; because they are artifacts a system either produces or does not. A single-tenant platform that generates audit-ready evidence, as the Kiteworks Control Plane does for CMMC Level 2 workflows, turns a &#8220;somewhat confident&#8221; self-attestation into a yes-or-no fact. Governance you cannot show is governance you cannot score.</span></p><h3><span>What This Means Monday Morning</span></h3><p><span>If you are building your own readiness metric &#8211; for CMMC or anything else &#8211; carry four rules out of this:</span></p><p><span>1. </span><strong><span>Make every input checkable.</span></strong><span> Score facts a third party could verify, not confidence a respondent self-reports. Eight yes-or-no indicators beat one five-point feeling.</span></p><p><span>2. </span><strong><span>Multiply necessary conditions; average only substitutes.</span></strong><span> If two dimensions must both be true, use a product so a low score on either caps the result. Reserve averaging for things that genuinely trade off.</span></p><p><span>3. </span><strong><span>Report the median next to the mean.</span></strong><span> The gap between them is your skew, and the skew tells you whether a weak tail is hiding inside a comfortable average.</span></p><p><span>4. </span><strong><span>Cross your axes before you trust your headline.</span></strong><span> A single blended number can conceal that your largest population is weak on every dimension at once.</span></p><p><span>The suspension paused the assessment. It did not pause the obligation, the </span><a href="http://kiteworks.com/risk-compliance-glossary/dfars/"><span>DFARS</span></a><span> clause, or the </span><a href="http://kiteworks.com/risk-compliance-glossary/false-claims-act/"><span>False Claims Act</span></a><span> exposure that rides on a self-attested score. The DIB knows it is busy. The harder question is whether busy is ready, and the only way to answer honestly is to pick the operator that refuses to lie.</span></p><p><span>Read the full report, </span><em><a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-cmmc-2-0-dib-readiness.pdf"><span>State of CMMC 2.0 in the DIB</span></a></em><span>.</span></p>]]></content:encoded></item><item><title><![CDATA[The Assessor Went Home. Your Liability Stayed.]]></title><description><![CDATA[The suspension paused the audit, not the obligation. The DIB is already spending like it knows the difference.]]></description><link>https://kiteworks.substack.com/p/the-assessor-went-home-your-liability</link><guid isPermaLink="false">https://kiteworks.substack.com/p/the-assessor-went-home-your-liability</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Wed, 02 Sep 2026 15:02:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mMIp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mMIp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mMIp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!mMIp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!mMIp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!mMIp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mMIp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:554182,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/213725097?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mMIp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!mMIp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!mMIp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!mMIp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55eb0c8e-bdc4-4860-9bfb-18cd924ab8df_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On July 13, 2026, the Department of War suspended Phase II third-party assessments under <a href="http://kiteworks.com/platform/compliance/cmmc-compliance/">CMMC 2.0</a>. Within days, some defense contractors read that headline as permission to exhale. That reading is a mistake, and a growing share of the Defense Industrial Base has already figured out why.</p><p>The suspension removed the assessor. It removed nothing else.</p><p><a href="http://kiteworks.com/risk-compliance-glossary/dfars/">DFARS</a> 252.204-7012 still binds you. <a href="http://kiteworks.com/risk-compliance-glossary/protect-cui-with-nist-800-171-compliance/">NIST SP 800-171</a> still defines the controls. Phase 1 self-assessment and your SPRS submission are still required, and the score you posted there is still a representation to the federal government. The <a href="http://kiteworks.com/risk-compliance-glossary/false-claims-act/">False Claims Act</a> still reaches that representation, and the Department of Justice&#8217;s Civil Cyber-Fraud Initiative is still the mechanism that enforces it. Take the <a href="http://kiteworks.com/risk-compliance-glossary/cmmc-third-party-assessor-organization-c3pao/">C3PAO</a> out of the room and every one of those obligations stays exactly where it was.</p><p>So the question is not whether the pause is real. It is real. The question is what a competent contractor does with the window it opened.</p><h3><span>What the pause changed -- and what it didn&#8217;t</span></h3><p><span>A new Kiteworks survey of 273 DIB organizations, all confirmed to do business with the DoW and all carrying an active </span><a href="http://kiteworks.com/platform/compliance/cmmc-compliance/"><span>CMMC 2.0</span></a><span> requirement, was fielded July 17 to 31 -- days after the suspension. It is one of the first clean reads of how the base behaved once the assessor walked out.</span></p><p><span>The base did not stand still. 98% took at least one concrete action after the suspension. Only 2% did nothing.</span></p><p><span>That reaction makes sense once you separate the audit from the accountability. The assessor was the thing that got paused. The accountability -- the self-attested score, the flow-down clauses, the fraud exposure -- did not move an inch. 84% of respondents told us they are concerned about </span><a href="http://kiteworks.com/risk-compliance-glossary/false-claims-act/"><span>False Claims Act</span></a><span> exposure. 92% engaged legal or compliance review after July 13. Nobody who reads </span><a href="http://kiteworks.com/risk-compliance-glossary/dfars/"><span>DFARS</span></a><span> closely mistook this for a reprieve.</span></p><h3><span>The gap between feeling covered and being covered</span></h3><p><span>Here is where it gets uncomfortable.</span></p><p><span>96% of respondents are confident their self-attested SPRS score would hold up under review. Read that again, then read what sits underneath it. Of the confident group, 60% have a current SPRS submission. 36% are on a </span><a href="http://kiteworks.com/risk-compliance-glossary/fedramp/"><span>FedRAMP</span></a><span>-authorized platform. Just 29% have both.</span></p><p><span>Fewer than three in ten who feel confident can fully back the feeling.</span></p><p><span>That is the confidence-evidence gap, and it is the single most dangerous posture in the current environment. A self-attestation you cannot substantiate is not a compliance status. It is an unpriced liability sitting in a federal database, waiting for a whistleblower or a DOJ inquiry to price it for you. The assessor&#8217;s absence does not shrink that liability. It just delays the day someone else checks your work.</span></p><h3><span>What the DIB is buying tells you the move</span></h3><p><span>Ignore what contractors say about their confidence. Watch what they are spending money on. Procurement is the honest signal.</span></p><p><span>89% are using or plan to adopt a </span><a href="http://kiteworks.com/risk-compliance-glossary/fedramp/"><span>FedRAMP</span></a><span>-authorized platform within six months. 93% say independent third-party authorization is essential or important to how they select a vendor. And despite the suspension, 96% have engaged a </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc-third-party-assessor-organization-c3pao/"><span>C3PAO</span></a><span> -- with 32% continuing a scheduled assessment voluntarily, paying for an audit no rule currently forces them to take.</span></p><p><span>That is not the behavior of a base that thinks the obligation went away. That is the behavior of a base that understands independent validation is the thing standing between a self-attestation and a defensible one.</span></p><p><span>The most telling number is about what would raise confidence. Asked what would most increase confidence in their compliance posture, respondents chose an </span><a href="http://kiteworks.com/regulatory-compliance/audit-log/"><span>audit trail</span></a><span> at 47%, </span><a href="http://kiteworks.com/risk-compliance-glossary/fedramp/"><span>FedRAMP</span></a><span> authorization at 36%, and legal review alone at just 11%. Evidence beats paperwork, four to one. The practitioners closest to this problem have already concluded that a memo from counsel does not survive contact with the Civil Cyber-Fraud Initiative. Contemporaneous, tamper-evident records do.</span></p><p><span>The external data says the same thing from a different angle. The </span><a href="https://www.verizon.com/business/resources/reports/dbir/"><span>Verizon 2026 Data Breach Investigations Report</span></a><span> found breaches with third-party involvement grew 60% year over year, to 48% of all breaches. The </span><a href="https://www.ibm.com/reports/data-breach"><span>IBM Cost of a Data Breach Report 2026</span></a><span> puts the cost of regulatory noncompliance at $201,112 per breach and </span><a href="http://kiteworks.com/risk-compliance-glossary/supply-chain-risk-management/"><span>supply-chain</span></a><span> compromise at $227,250 -- the top cost-increasing factor. Your exposure runs through your subcontractors and your evidence, not through your intentions.</span></p><h3><span>The architectural question underneath the checklist</span></h3><p><span>You can generate audit evidence by hand. Screenshots, spreadsheets, quarterly attestations stapled together the week before a review. Every contractor who has tried it knows how that ends: gaps, reconstruction, and a record that looks manufactured because it was.</span></p><p><span>The alternative is to make evidence a byproduct of how sensitive data moves, so the </span><a href="http://kiteworks.com/regulatory-compliance/audit-log/"><span>audit trail</span></a><span> writes itself as work happens rather than getting assembled after the fact. That is an architectural choice, not a policy one. Platforms built on single-tenant isolation that support CMMC Level 2 requirements and generate audit-ready evidence -- </span><a href="https://www.kiteworks.com/"><span>Kiteworks</span></a><span> is one, FedRAMP High In Process and FedRAMP Moderate Authorized -- treat the evidence trail as the point, not an export you scramble to produce. The distinction matters because the thing DOJ asks for is not your confidence. It is your records, dated, complete, and matching what you attested.</span></p><h3><span>What to do before the Reform Task Force reports back</span></h3><p><span>The pause is a window. Windows close. 58% of the base expects Phase II to return in a modified form; only 4% think it disappears. Meanwhile 93% plan to comment on the DoW&#8217;s RFI. The people betting this is over are a rounding error. Do not join them.</span></p><p><span>Here is what a competent contractor does this week:</span></p><ol><li><p><strong><span>Make your SPRS submission current.</span></strong><span> If the score in the database predates your last environment change, it is stale, and stale plus attested is the exact fact pattern the </span><a href="http://kiteworks.com/risk-compliance-glossary/false-claims-act/"><span>False Claims Act</span></a><span> was built for. Fix the record before someone else audits it.</span></p></li><li><p><strong><span>Generate contemporaneous audit evidence, not reconstructed evidence.</span></strong><span> Capture how sensitive data moves now, while you can document it in real time. Evidence created after an inquiry starts is worth a fraction of evidence created before one.</span></p></li><li><p><strong><span>Get independent validation while it&#8217;s voluntary.</span></strong><span> The 32% continuing their </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc-third-party-assessor-organization-c3pao/"><span>C3PAO</span></a><span> engagement are not wasting money. They are buying a defensible position at a moment when the market for assessors is not yet a bottleneck.</span></p></li><li><p><strong><span>File a comment on the RFI.</span></strong><span> The rule is being rewritten right now. The contractors shaping what Phase II looks like when it returns are the ones in the room this month, not the ones reacting to it next year.</span></p></li></ol><p><span>The assessor went home. Your name is still on the score. Close the gap between the two while you still control the timing -- because when Phase II returns, you won&#8217;t.</span></p><p><span>Read the full report, </span><em><a href="https://www.kiteworks.com/cmmc-compliance/cmmc-2-0-dib-compliance-report/"><span>State of CMMC 2.0 in the DIB</span></a></em><span>, for the complete data on where the base stands and what separates the audit-ready from the exposed.</span>On July 13, 2026, the Department of War suspended Phase II third-party assessments under <a href="http://kiteworks.com/platform/compliance/cmmc-compliance/">CMMC 2.0</a>. Within days, some defense contractors read that headline as permission to exhale. That reading is a mistake, and a growing share of the Defense Industrial Base has already figured out why.</p><p>The suspension removed the assessor. It removed nothing else.</p><p><a href="http://kiteworks.com/risk-compliance-glossary/dfars/">DFARS</a> 252.204-7012 still binds you. <a href="http://kiteworks.com/risk-compliance-glossary/protect-cui-with-nist-800-171-compliance/">NIST SP 800-171</a> still defines the controls. Phase 1 self-assessment and your SPRS submission are still required, and the score you posted there is still a representation to the federal government. The <a href="http://kiteworks.com/risk-compliance-glossary/false-claims-act/">False Claims Act</a> still reaches that representation, and the Department of Justice&#8217;s Civil Cyber-Fraud Initiative is still the mechanism that enforces it. Take the <a href="http://kiteworks.com/risk-compliance-glossary/cmmc-third-party-assessor-organization-c3pao/">C3PAO</a> out of the room and every one of those obligations stays exactly where it was.</p><p>So the question is not whether the pause is real. It is real. The question is what a competent contractor does with the window it opened.</p><h3><span>What the pause changed -- and what it didn&#8217;t</span></h3><p><span>A new Kiteworks survey of 273 DIB organizations, all confirmed to do business with the DoW and all carrying an active </span><a href="http://kiteworks.com/platform/compliance/cmmc-compliance/"><span>CMMC 2.0</span></a><span> requirement, was fielded July 17 to 31 -- days after the suspension. It is one of the first clean reads of how the base behaved once the assessor walked out.</span></p><p><span>The base did not stand still. 98% took at least one concrete action after the suspension. Only 2% did nothing.</span></p><p><span>That reaction makes sense once you separate the audit from the accountability. The assessor was the thing that got paused. The accountability -- the self-attested score, the flow-down clauses, the fraud exposure -- did not move an inch. 84% of respondents told us they are concerned about </span><a href="http://kiteworks.com/risk-compliance-glossary/false-claims-act/"><span>False Claims Act</span></a><span> exposure. 92% engaged legal or compliance review after July 13. Nobody who reads </span><a href="http://kiteworks.com/risk-compliance-glossary/dfars/"><span>DFARS</span></a><span> closely mistook this for a reprieve.</span></p><h3><span>The gap between feeling covered and being covered</span></h3><p><span>Here is where it gets uncomfortable.</span></p><p><span>96% of respondents are confident their self-attested SPRS score would hold up under review. Read that again, then read what sits underneath it. Of the confident group, 60% have a current SPRS submission. 36% are on a </span><a href="http://kiteworks.com/risk-compliance-glossary/fedramp/"><span>FedRAMP</span></a><span>-authorized platform. Just 29% have both.</span></p><p><span>Fewer than three in ten who feel confident can fully back the feeling.</span></p><p><span>That is the confidence-evidence gap, and it is the single most dangerous posture in the current environment. A self-attestation you cannot substantiate is not a compliance status. It is an unpriced liability sitting in a federal database, waiting for a whistleblower or a DOJ inquiry to price it for you. The assessor&#8217;s absence does not shrink that liability. It just delays the day someone else checks your work.</span></p><h3><span>What the DIB is buying tells you the move</span></h3><p><span>Ignore what contractors say about their confidence. Watch what they are spending money on. Procurement is the honest signal.</span></p><p><span>89% are using or plan to adopt a </span><a href="http://kiteworks.com/risk-compliance-glossary/fedramp/"><span>FedRAMP</span></a><span>-authorized platform within six months. 93% say independent third-party authorization is essential or important to how they select a vendor. And despite the suspension, 96% have engaged a </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc-third-party-assessor-organization-c3pao/"><span>C3PAO</span></a><span> -- with 32% continuing a scheduled assessment voluntarily, paying for an audit no rule currently forces them to take.</span></p><p><span>That is not the behavior of a base that thinks the obligation went away. That is the behavior of a base that understands independent validation is the thing standing between a self-attestation and a defensible one.</span></p><p><span>The most telling number is about what would raise confidence. Asked what would most increase confidence in their compliance posture, respondents chose an </span><a href="http://kiteworks.com/regulatory-compliance/audit-log/"><span>audit trail</span></a><span> at 47%, </span><a href="http://kiteworks.com/risk-compliance-glossary/fedramp/"><span>FedRAMP</span></a><span> authorization at 36%, and legal review alone at just 11%. Evidence beats paperwork, four to one. The practitioners closest to this problem have already concluded that a memo from counsel does not survive contact with the Civil Cyber-Fraud Initiative. Contemporaneous, tamper-evident records do.</span></p><p><span>The external data says the same thing from a different angle. The </span><a href="https://www.verizon.com/business/resources/reports/dbir/"><span>Verizon 2026 Data Breach Investigations Report</span></a><span> found breaches with third-party involvement grew 60% year over year, to 48% of all breaches. The </span><a href="https://www.ibm.com/reports/data-breach"><span>IBM Cost of a Data Breach Report 2026</span></a><span> puts the cost of regulatory noncompliance at $201,112 per breach and </span><a href="http://kiteworks.com/risk-compliance-glossary/supply-chain-risk-management/"><span>supply-chain</span></a><span> compromise at $227,250 -- the top cost-increasing factor. Your exposure runs through your subcontractors and your evidence, not through your intentions.</span></p><h2><span>The architectural question underneath the checklist</span></h2><p><span>You can generate audit evidence by hand. Screenshots, spreadsheets, quarterly attestations stapled together the week before a review. Every contractor who has tried it knows how that ends: gaps, reconstruction, and a record that looks manufactured because it was.</span></p><p><span>The alternative is to make evidence a byproduct of how sensitive data moves, so the </span><a href="http://kiteworks.com/regulatory-compliance/audit-log/"><span>audit trail</span></a><span> writes itself as work happens rather than getting assembled after the fact. That is an architectural choice, not a policy one. Platforms built on single-tenant isolation that support CMMC Level 2 requirements and generate audit-ready evidence -- </span><a href="https://www.kiteworks.com/"><span>Kiteworks</span></a><span> is one, FedRAMP High In Process and FedRAMP Moderate Authorized -- treat the evidence trail as the point, not an export you scramble to produce. The distinction matters because the thing DOJ asks for is not your confidence. It is your records, dated, complete, and matching what you attested.</span></p><h3><span>What to do before the Reform Task Force reports back</span></h3><p><span>The pause is a window. Windows close. 58% of the base expects Phase II to return in a modified form; only 4% think it disappears. Meanwhile 93% plan to comment on the DoW&#8217;s RFI. The people betting this is over are a rounding error. Do not join them.</span></p><p><span>Here is what a competent contractor does this week:</span></p><ol><li><p><strong><span>Make your SPRS submission current.</span></strong><span> If the score in the database predates your last environment change, it is stale, and stale plus attested is the exact fact pattern the </span><a href="http://kiteworks.com/risk-compliance-glossary/false-claims-act/"><span>False Claims Act</span></a><span> was built for. Fix the record before someone else audits it.</span></p></li><li><p><strong><span>Generate contemporaneous audit evidence, not reconstructed evidence.</span></strong><span> Capture how sensitive data moves now, while you can document it in real time. Evidence created after an inquiry starts is worth a fraction of evidence created before one.</span></p></li><li><p><strong><span>Get independent validation while it&#8217;s voluntary.</span></strong><span> The 32% continuing their </span><a href="http://kiteworks.com/risk-compliance-glossary/cmmc-third-party-assessor-organization-c3pao/"><span>C3PAO</span></a><span> engagement are not wasting money. They are buying a defensible position at a moment when the market for assessors is not yet a bottleneck.</span></p></li><li><p><strong><span>File a comment on the RFI.</span></strong><span> The rule is being rewritten right now. The contractors shaping what Phase II looks like when it returns are the ones in the room this month, not the ones reacting to it next year.</span></p></li></ol><p><span>The assessor went home. Your name is still on the score. Close the gap between the two while you still control the timing -- because when Phase II returns, you won&#8217;t.</span></p><p><span>Read the full report, </span><em><a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-cmmc-2-0-dib-readiness.pdf"><span>State of CMMC 2.0 in the DIB</span></a></em><span>, for the complete data on where the base stands and what separates the audit-ready from the exposed.</span></p>]]></content:encoded></item><item><title><![CDATA[Your Coding Agent Runs as You. That’s the Vulnerability.]]></title><description><![CDATA[Hazmat doesn&#8217;t harden the AI agent. It locks up the human account the agent inherited.]]></description><link>https://kiteworks.substack.com/p/your-coding-agent-runs-as-you-thats</link><guid isPermaLink="false">https://kiteworks.substack.com/p/your-coding-agent-runs-as-you-thats</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Tue, 01 Sep 2026 15:02:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ioEW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ioEW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ioEW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!ioEW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!ioEW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!ioEW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ioEW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:619479,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/213606300?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ioEW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!ioEW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!ioEW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!ioEW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1550986c-0749-43cd-8f7e-bf71174e8a21_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Picture a Tuesday morning that plays out on laptops everywhere: a developer opens a terminal, types <span>claude</span>, and hands an AI coding agent the keys to a Git repository. The agent reads the codebase, writes a patch, runs the test suite. It also, without anyone deciding it, has read access to the SSH key at <span>~/.ssh/id_ed25519</span>, the AWS <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> in <span>~/.aws/credentials</span>, and every other file the developer has touched in a decade of accumulated home-directory sprawl.</p><p>That is not a hypothetical. It is how every terminal-based coding agent runs today, by default, on nearly every laptop in nearly every engineering org. On August 17, 2026, Help Net Security profiled a tool built specifically to close that gap: <a href="https://www.helpnetsecurity.com/2026/08/17/hazmat-open-source-ai-coding-agent-containment/">Hazmat</a>, an open-source project that wraps Claude Code, Codex, OpenCode, Cursor Agent, and other harnesses inside a separate operating-system user account.</p><p>Here&#8217;s the whole game: an agent launched the ordinary way runs as you. Hazmat&#8217;s own framing of the problem, quoted directly, is blunt about what that means: &#8220;An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a>, and the pile of configuration in your home directory that has accumulated over years.&#8221; Contain the account, not just the agent, and the credential-harvesting problem disappears at the OS layer. That&#8217;s the pitch. It is a good one. It is also not the whole problem, and the source article, to its credit, does not pretend otherwise.</p><h3>What Hazmat Actually Does</h3><p>Hazmat gives the agent its own home directory and shares only the project directory the operator points it at. On macOS, the tool <a href="https://github.com/dredozubov/hazmat">backs up the project, builds a per-session sandbox policy, switches to the dedicated agent account, and starts the harness with a firewall rule already in force</a>. Linux runs natively. An Apple container-tooling backend sits behind an experimental flag.</p><p>Before any of that happens, one command prints the session&#8217;s terms in plain language: the directory the agent can write to, the paths it can only read, whether it can reach the network or any services, and whether a backup runs first. Most containment tools ask you to trust the sandbox. Hazmat shows you the contract before you sign it.</p><p>The demo is simple: a script writes a file into a throwaway project while a private key sitting in the real home directory comes back unreadable. About 5.5 percent of the codebase is a formal TLA+ specification, a mathematically checkable model of how the containment boundary should behave. That is a real engineering signal, and also a narrow one. What got verified is the model on paper. The Go binary you actually install is separate work, with its own bugs, and the project&#8217;s own documentation says so.</p><h3>The Pattern: Every Identity Now Has 108 Roommates</h3><p>Hazmat is solving a version of a problem the rest of enterprise security is only starting to name. Palo Alto Networks&#8217; <a href="https://www.paloaltonetworks.com/idira/idira-identity-security-landscape">2026 Identity Security Landscape Report</a>, a survey of more than 2,900 security decision-makers, found that machine identities, including AI agents, now outnumber human identities 109 to 1. Ninety-six percent of respondents said human identities already carry access far beyond what their roles require. Layer a coding agent that inherits the full read scope of whoever launched it on top of that ratio, and the exposure compounds. It doesn&#8217;t average out. It multiplies.</p><p>Accountability hasn&#8217;t caught up with deployment speed. Gravitee&#8217;s <a href="https://www.gravitee.io/state-of-ai-agent-security">State of AI Agent Security Report 2026</a>, a survey of 750 senior technology leaders across the UK and US updated in April 2026, found that 85 percent of organizations have no formal accountability structure for AI agent behavior, and only 7.2 percent have a named individual accountable for what an agent does. Read that again. Seven percent. The agent fleet is doubling every few months. The org chart for who owns it is not.</p><h3>Why the Math Got Worse</h3><p>None of this is new in kind. What&#8217;s new is scale and default trust. Coding agents in 2026 run longer, touch more of the filesystem, and get invoked with fewer human approvals per action than the chat-based assistants of two years ago. Hazmat&#8217;s own design notes make the point plainly: approval prompts are a workflow control, not an authority boundary. If a process can read your secrets, a bad instruction, a poisoned dependency, or a prompt-injected repository can use that authority just as easily as you can.</p><p>That caveat matters for how you read what follows. Hazmat contains what the agent&#8217;s operating-system process can reach. It says nothing about the content the payload was hunting for in the first place, because on most laptops that content is a file on disk. In an enterprise, it&#8217;s rarely a file. It&#8217;s a record in a content repository, a document management system, an <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer/">MFT</a> server, a CRM export sitting behind a login the agent was handed to do its job.</p><h3>The Architectural Question</h3><p>That&#8217;s the boundary Hazmat cannot see past, and it&#8217;s the one enterprise content governance has to answer. Kiteworks&#8217; own <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">2026 Forecast Report</a>, a survey of 225 security, IT, and risk leaders across 10 industries, found that 63 percent of organizations cannot enforce purpose limitations on the AI agents they&#8217;ve already put into production, 60 percent cannot terminate a misbehaving agent, and 33 percent have no evidence-quality <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> at all. Same failure mode as Hazmat&#8217;s premise. Different layer.</p><p>Kiteworks&#8217; <a href="https://www.kiteworks.com/platform/security/mcp-ai-integration/">Secure MCP Server</a> is worth naming here, not as the fix, but as the same principle applied one layer up. Kiteworks enforces per-request <a href="https://www.kiteworks.com/risk-compliance-glossary/attribute-based-access-control/">RBAC and ABAC</a> so an agent&#8217;s reach into enterprise content is scoped to what policy permits, not to what the human or system account that invoked it happens to be able to read, and it keeps <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> out of the LLM&#8217;s context window so a compromised or drifting agent has nothing to harvest even if it gets that far. The Kiteworks Control Plane governs that access, use, and exchange of sensitive content the same way for a human user and an AI agent under one policy, not as a separate track for machines acting on their own.</p><p>Be precise about what that buys you. Hazmat contains the agent&#8217;s host environment: the filesystem, the network egress, the credential store on the machine it runs on. Kiteworks governs what the agent may retrieve from the enterprise content repositories it&#8217;s allowed to touch. The two solve adjacent problems at different layers of the same stack, and an organization running AI coding agents at scale needs both, not one instead of the other. Neither tool inspects a prompt for an injection payload. That is a different control, and treating either one as if it did is a mistake.</p><h3>What This Means for You Now</h3><p><span>1. </span>Inventory every machine running an AI coding agent with default <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> in scope. Isolate the ~/.ssh and ~/.aws directories first, not last.</p><p><span>2. </span>Pilot OS-level containment, Hazmat or an equivalent, for any agent session running longer than a single approved task.</p><p><span>3. </span>Ask your AI governance owner, by name, what the agent can reach in your content systems, not just on the endpoint. If nobody can answer that, you&#8217;ve found your gap.</p><p><span>4. </span>Extend <a href="http://kiteworks.com/risk-compliance-glossary/role-based-access-control/">RBAC</a> and <a href="http://kiteworks.com/risk-compliance-glossary/attribute-based-access-control/">ABAC</a> enforcement to agent identities in your content platforms before you extend agent count. Scope precedes scale.</p><p><span>5. </span>Log every credential path in the trust chain, human and agent, and audit both to the same evidentiary standard.</p><p>Hazmat is a real answer to a real problem, on one machine, at one layer. The agent still runs as you everywhere else.</p>]]></content:encoded></item><item><title><![CDATA[MCP07 Just Made “Whoever Asks” an Audit Finding.]]></title><description><![CDATA[No breach sits behind this one. Three OWASP lists just confirmed your AI stack still has no identity layer for machines, and nobody had to get hacked to prove it.]]></description><link>https://kiteworks.substack.com/p/mcp07-just-made-whoever-asks-an-audit</link><guid isPermaLink="false">https://kiteworks.substack.com/p/mcp07-just-made-whoever-asks-an-audit</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Mon, 31 Aug 2026 15:01:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PLXQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PLXQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PLXQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!PLXQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!PLXQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!PLXQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PLXQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:644751,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/213042403?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PLXQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!PLXQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!PLXQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!PLXQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F98f2c792-a5b5-4962-9d03-aa0bd81a461e_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Picture a plausible Tuesday morning: an agent in your environment calls a tool through an <a href="http://kiteworks.com/platform/security/mcp-ai-integration/">MCP</a> server to pull a file, update a record, or kick off a workflow. Nobody in that chain checks who is asking, beyond the fact that something asked and the server answered. The scene is illustrative. The underlying gap is not. It&#8217;s the literal finding sitting inside entry MCP07 of the OWASP MCP Top 10, and it should bother you more than the last CVE alert you triaged. There&#8217;s no incident report attached to it. That&#8217;s the point.</p><h3>Whoever Asks, Gets the Tool Call</h3><p><a href="https://securityboulevard.com/2026/08/the-owasp-llm-top-10-was-the-warm-up-what-comes-next/">Security Boulevard&#8217;s coverage</a>, syndicating an <a href="https://www.imperva.com/blog/owasp-llm-top-10-what-comes-next-agentic-mcp/">Imperva analysis</a> published in August 2026, lines up three OWASP lists against three layers of an AI system. The <a href="https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/">OWASP Top 10 for LLM Applications (2025)</a> covers the conversation layer: prompt injection, sensitive information disclosure, system prompt leakage, improper output handling, and unbounded consumption make up five of its ten entries. The <a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">OWASP Top 10 for Agentic Applications (2026)</a>, released in December 2025 with ten ASI-prefixed entries running from agent goal hijack (ASI01) to rogue agents (ASI10), covers the action layer: what happens once a system stops answering and starts doing.</p><p>The third list is the one worth stopping on. The <a href="https://owasp.org/www-project-mcp-top-10/">OWASP MCP Top 10</a>, still in beta, covers what Imperva&#8217;s piece calls the connective tissue: the Model Context Protocol wiring that connects an assistant to the tools and data it acts on. MCP07 addresses insufficient authentication and authorization on tool calls. On the question of who may call a tool, the piece&#8217;s framing is blunt: the answer is whoever asks. That&#8217;s a missing identity layer for machines, and it now has a project number instead of just a bad feeling.</p><h3>MCP09 Gave Shadow AI a Number, Not a Cure</h3><p>Sitting two entries down the same beta list is MCP09: shadow <a href="http://kiteworks.com/platform/security/mcp-ai-integration/">MCP</a> servers, frequently running on default <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a>, that nobody in security ever inventoried.</p><p>Security Boulevard&#8217;s characterization is exact. The shadow AI problem now has an OWASP number.</p><p>Scale that against where machine identity actually sits today. Palo Alto Networks&#8217; 2026 Identity Security Landscape report, based on a vendor-sponsored survey of 2,930 cybersecurity decision-makers, found that <a href="https://www.helpnetsecurity.com/2026/05/14/2026-identity-security-landscape-report/">machine identities now outnumber human identities 109 to 1</a>, up from 82 to 1 a year earlier. Of those 109, 79 are AI agents. Read that as a directional finding from one report, not settled fact. But even directionally, it means every MCP07 gap and every MCP09 shadow server sits underneath a machine-identity population that grew faster than most governance programs did.</p><h3>63% Can&#8217;t Enforce Purpose Limits. That&#8217;s the Math That Changed</h3><p>Here&#8217;s why this beta checklist lands differently than it would have a year ago. In the <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Kiteworks Data Security and Compliance Risk: 2026 Forecast Report</a>, 100% of organizations surveyed have agentic AI on their roadmap and 51% already run agents in production. Yet 63% cannot enforce purpose limitations on those agents, and 60% cannot terminate one that starts misbehaving.</p><p>An agent you cannot purpose-bind and cannot kill is precisely the agent MCP07 describes: one that gets a tool call approved because it asked, not because anyone verified it should. And an environment where more than half of organizations already run agents in production, without a full inventory of what&#8217;s calling what, is precisely the environment MCP09 describes. The two OWASP entries aren&#8217;t describing a future risk. They&#8217;re describing the default state of AI programs that scaled adoption ahead of authorization. Call it the ask-and-you-shall-receive default: the tool call goes through because nothing in the chain was built to say no.</p><h3>The Fix Is Architectural, Not Incident-Driven</h3><p>Be clear about what this piece is and isn&#8217;t. There&#8217;s no breach disclosure behind MCP07 or MCP09, no regulator citation, no forensic timeline. The fit here is standards and architecture, not incident response. That distinction matters, and so does a second one: Security Boulevard&#8217;s own source article is syndicated Imperva content, and it closes on an Imperva product pitch. That doesn&#8217;t make the underlying OWASP mapping wrong. It means the argument should be evaluated against the checklist, not against either vendor&#8217;s sales page, including this one.</p><p>Patching individual <a href="http://kiteworks.com/platform/security/mcp-ai-integration/">MCP</a> server configs one at a time is the tactical response, and it stops scaling the moment your organization&#8217;s MCP footprint matches a 51%-in-production adoption curve. The architectural alternative is a governed access layer that authenticates and scopes every tool call the same way, regardless of which server or which agent is asking, so there&#8217;s no server left ungoverned enough to go &#8220;shadow.&#8221; The <a href="https://www.kiteworks.com/platform/security/mcp-ai-integration/">Kiteworks Secure MCP Server</a> is one example built on that premise: every file, folder, or record operation an agent requests is evaluated in real time against <a href="http://kiteworks.com/risk-compliance-glossary/role-based-access-control/">role-based</a> and <a href="http://kiteworks.com/risk-compliance-glossary/attribute-based-access-control/">attribute-based access policy</a>, <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> never surface inside the model&#8217;s context, and the resulting <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> lands in the same log a human&#8217;s activity does.</p><p>That last point is the one to hold onto. This isn&#8217;t a case of extending governance to agents that were previously left alone while humans stayed supervised. An agent connecting through the MCP server inherits the access of the human or service account that authorized it, evaluated under the same policy engine, not a separate one carved out for machines. Kiteworks&#8217; own framing for this is that regulators regulate data, not the model or agent framework moving it. <a href="http://kiteworks.com/risk-compliance-glossary/hipaa/">HIPAA</a>, <a href="http://kiteworks.com/risk-compliance-glossary/cmmc/">CMMC</a>, and <a href="http://kiteworks.com/risk-compliance-glossary/gdpr/">GDPR</a> don&#8217;t ask whether a person or a process touched the record. They ask whether the access was authorized, logged, and defensible. MCP07 and MCP09 are the OWASP-numbered version of that same question, aimed at the one layer, tool-call authorization, most programs haven&#8217;t gotten to yet.</p><h3>What to Do Now</h3><p>Here&#8217;s the whole game: you don&#8217;t need an incident to justify fixing this. You need an inventory and an owner.</p><p><span>1. </span>Pull the <a href="https://owasp.org/www-project-mcp-top-10/">OWASP MCP Top 10</a> beta list and score every MCP server you run against it, starting with MCP07 and MCP09.</p><p><span>2. </span>Inventory every MCP server actually running in your environment, not just the ones IT provisioned. If you can&#8217;t produce that list today, MCP09 already describes your gap.</p><p><span>3. </span>Ask whoever owns your AI agent program one direct question: when an agent calls a tool, what identity gets checked, and can you produce the log that proves it. &#8220;Whoever asks&#8221; is not an acceptable answer.</p><p><span>4. </span>Map all three OWASP lists, LLM, Agentic, and MCP, against your AI governance committee&#8217;s charter. If nobody owns the connective-tissue layer, name an owner this week.</p><p><span>5. </span>Treat this as an audit-evidence problem, not a threat-hunting problem. The question a regulator or a board member asks isn&#8217;t whether you detected an attack. It&#8217;s whether you can prove who was authorized to call that tool, and when.</p><p>OWASP didn&#8217;t find an incident this month. It found the gap between what your agents can already do and what you can prove they were allowed to do. That gap is the whole story, and it was there long before anyone gave it a number.</p>]]></content:encoded></item><item><title><![CDATA[Nearly Half Your Enterprise AI Traffic Isn’t Yours to Govern.]]></title><description><![CDATA[Akamai&#8217;s LayerX platform puts the number at 47.11%. The scarier finding is what your DLP still can&#8217;t see once an employee is logged in and typing.]]></description><link>https://kiteworks.substack.com/p/nearly-half-your-enterprise-ai-traffic</link><guid isPermaLink="false">https://kiteworks.substack.com/p/nearly-half-your-enterprise-ai-traffic</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Fri, 28 Aug 2026 15:02:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!VtCG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!VtCG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!VtCG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!VtCG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!VtCG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!VtCG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!VtCG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:580590,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/213040563?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!VtCG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!VtCG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!VtCG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!VtCG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccd2ec0c-5525-4d35-8221-4f71760243d5_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In late January 2026, <a href="https://techcrunch.com/2026/01/28/trumps-acting-cybersecurity-chief-uploaded-sensitive-government-docs-to-chatgpt/">TechCrunch reported</a> that Madhu Gottumukkala, the acting director of the U.S. Cybersecurity and Infrastructure Security Agency, had uploaded at least four documents marked &#8220;for official use only&#8221; to the public version of ChatGPT the previous summer. He had requested permission to use ChatGPT at an agency that blocks it for most employees over data retention concerns. Sensors caught the activity roughly a week after it started. Nobody phished a credential or exploited a CVE. The nation&#8217;s top civilian cyber-defense official simply pasted sensitive material into a chat window because it was the fastest way to finish his work.</p><p>That is not a hacking story. It is the story Akamai&#8217;s new State of the Internet: Enterprise AI Usage Risk Report 2026 is telling. The report, built on data from <a href="https://www.akamai.com/security">Akamai&#8217;s LayerX platform</a> (Akamai acquired LayerX earlier this year), argues the defining AI risk facing your organization stopped being &#8220;who can access AI.&#8221; The real exposure now is what a well-meaning employee shares with a tool they are fully authorized to use, one prompt at a time, in pieces too small for any control you own to flag.</p><h3><span>The Fragmentation Problem Your DLP Was Never Built to Catch</span></h3><p>Legacy <a href="http://kiteworks.com/risk-compliance-glossary/data-loss-prevention-dlp/">DLP</a> assumes sensitive data moves through named channels (an email attachment, a file upload, an <a href="http://kiteworks.com/risk-compliance-glossary/sftp/">SFTP</a> transfer). AI does not move data that way. It moves through prompts, conversational context, code snippets, screenshots, copied text, and generated responses, and Akamai&#8217;s data shows how granular that fragmentation gets.</p><p>The average enterprise AI conversation contains 5.09 prompts, but the median is 2. The top 5% of conversations run 18 prompts or more. Usage concentrates the same way. The average user holds 36 conversations, the bottom half of users 12 or fewer, and the top 5% at least 144. A small population of power users drives a disproportionate share of activity, shares more sensitive business context per session, and increasingly delegates execution-level work to an AI agent.</p><p>None of that trips a single alert. It shows up as hundreds of unremarkable interactions that, stitched together, reconstruct exactly what your <a href="http://kiteworks.com/secure-file-transfer/data-classification-what-it-is-types-and-best-practices/">data classification</a> policy exists to protect. In a follow-up survey to its own <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Kiteworks Data Security and Compliance Risk: 2026 Forecast Report</a>, Kiteworks found that among 459 security and compliance leaders, 73% had no purpose-binding controls restricting what data their AI agents can reach, and half could not produce a complete AI data access <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit record</a> within one business day. That is not a detection gap. It is an evidence gap, and evidence gaps are what a regulator asks about first.</p><h3><span>Half the Traffic Runs Through Accounts Nobody Manages</span></h3><p>Fragmentation would be manageable if you at least knew whose data was fragmenting. You mostly do not. Akamai found that 47.11% of enterprise AI conversations run through personal identities rather than corporate-managed accounts, close to a coin flip on whether a given AI interaction sits inside your identity perimeter at all. Worse, 14.4% of conversations initiated from a corporate email address run on a personal freemium subscription instead of an enterprise license, so a corporate-looking login can still feed a vendor&#8217;s public training pipeline.</p><p>The split sharpens by platform. ChatGPT runs 61.36% personal, Copilot 63.92% personal, Claude 61.09% personal. DeepSeek runs 99.83% personal, essentially unmanaged, just as <a href="https://www.cnbc.com/2026/06/17/us-deepseek-blacklist-cxmt-national-security-risks-.html">U.S. officials</a> weigh adding the company to the Commerce Department&#8217;s Entity List over concerns it supports Chinese military and intelligence objectives. Purpose-built enterprise offerings look nothing alike. Gemini Enterprise runs 98.15% corporate; Copilot for M365 runs 90.55% corporate. The identity gap isn&#8217;t inherent to AI. It&#8217;s a function of which product got deployed and enforced.</p><p><a href="https://www.verizon.com/business/resources/reports/dbir/">Verizon&#8217;s 2026 Data Breach Investigations Report</a> independently corroborates the shape of the problem. It found 45% of employees are now regular AI users on corporate devices, up from 15% the prior year, and that source code, not PII, is the single most common data type leaving the enterprise for external GenAI tools. The identity gap and the fragmentation gap are the same gap, described from two angles.</p><h3><span>Attackers Have Stopped Bothering With the Human</span></h3><p>The report&#8217;s fifth risk category should worry a CISO most. AI agents now operate inside the enterprise with broad access granted for speed, and attackers increasingly target them directly rather than the person who deployed them.</p><p>LayerX researchers demonstrated the shift twice in the past year. In <a href="https://layerxsecurity.com/blog/cometjacking-how-one-click-can-turn-perplexitys-comet-ai-browser-against-you/">CometJacking</a>, a single malicious link hijacked Perplexity&#8217;s Comet browser agent through indirect <a href="http://kiteworks.com/risk-compliance-glossary/phishing-attacks/">prompt injection</a>, instructing it to encode Gmail and Calendar contents in Base64 and exfiltrate them to an external server. In <a href="https://layerxsecurity.com/blog/cursorjacking-every-cursor-user-is-vulnerable-to-api-key-theft-by-rogue-extensions/">CursorJacking</a>, a rogue browser extension disguised as a theme or productivity add-on queried the Cursor coding assistant&#8217;s unprotected local database directly, extracting <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">API keys</a> and session tokens with no user interaction. LayerX scored the flaw 8.2 on CVSS.</p><p>Neither attack touched the human user&#8217;s <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a>. Both targeted the agent acting on the employee&#8217;s behalf, because that agent already holds the privileged access an attacker wants (email, calendar, active sessions, connected repositories). <a href="https://www.crowdstrike.com/en-us/global-threat-report/">CrowdStrike&#8217;s 2026 Global Threat Report</a> puts a number on the wider trend, an 89% year-over-year increase in operations by AI-enabled adversaries. The lesson isn&#8217;t that agents should be walked back. It&#8217;s that an agent acting on an employee&#8217;s behalf needs the same identity governance, monitoring, and revocation rights you&#8217;d demand for the employee.</p><h3><span>Governance Must Cover the Agent and the Human, Not Just One</span></h3><p>The fix is neither &#8220;block AI&#8221; nor &#8220;trust the vendor&#8217;s terms of service,&#8221; and both intuitive answers fail. Blocking AI pushes power users toward the personal accounts you can&#8217;t see at all, the 47.11% problem restated. Trusting a vendor&#8217;s data handling policy does nothing about a rogue extension or a hijacked agent walking in through the front door.</p><p>Akamai&#8217;s mitigation framework instead calls for treating prompts, uploads, downloads, and copy and paste activity as inspectable content in context, rather than as files run through pattern matching, and for extending identity and audit controls to AI agents as a new class of enterprise identity, governed alongside the humans who deploy them. Kiteworks&#8217; original 2026 Forecast Report had predicted this collision was coming. Every organization surveyed expected agentic AI on its 2026 roadmap; fewer than 40% expected containment controls ready to manage it. The follow-up survey found the gap had widened, not closed.</p><p>A handful of vendors are now building toward exactly that architecture, one policy plane governing sensitive content across email, file transfer, web forms, and AI interactions under a single evidence-quality <a href="https://www.kiteworks.com/regulatory-compliance/audit-log/">audit trail</a>, whether the party on the other end is a person or an agent acting on their behalf. Kiteworks&#8217; platform, built on a <a href="http://kiteworks.com/platform/security/hardened-virtual-appliance">hardened virtual appliance</a> with <a href="http://kiteworks.com/risk-compliance-glossary/fips/">FIPS 140-3</a> validated <a href="http://kiteworks.com/secure-file-sharing/public-vs-private-key-encryption/">encryption</a>, is one example of a system designed around that premise rather than around detecting AI misuse after the fact.</p><h3><span>The Three Questions to Ask Before Your Next Board Update</span></h3><p>Get honest answers to these before a regulator, auditor, or board member asks first.</p><p><span>1. </span>Who are your AI power users, and what share of your sensitive data exposure do they account for? App-access lists won&#8217;t show you; conversation depth will.</p><p><span>2. </span>Which AI logins on your network are personal or freemium accounts, regardless of what email domain signed up? Treat every one as unmanaged until proven otherwise.</p><p><span>3. </span>Can prompts, uploads, downloads, and copy and paste into AI tools be inspected in real time, the way file transfers already are?</p><p><span>4. </span>Do you have an inventory of every AI agent running in your environment, what it can access, and one control point to revoke that access?</p><p><span>5. </span>If asked for a complete AI data access audit trail tomorrow, could your team produce it inside a business day, not a sprint?</p><p>The CISA leak didn&#8217;t require a hacker. Neither will the next one.</p>]]></content:encoded></item><item><title><![CDATA[OpenTelemetry Logs What AI Agents Did. Not Who Approved It.]]></title><description><![CDATA[The new CNCF standard finally gives AI governance a shared evidence layer. It was never built to answer the one question a regulator actually asks.]]></description><link>https://kiteworks.substack.com/p/opentelemetry-logs-what-ai-agents</link><guid isPermaLink="false">https://kiteworks.substack.com/p/opentelemetry-logs-what-ai-agents</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Thu, 27 Aug 2026 15:02:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!10vy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!10vy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!10vy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!10vy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!10vy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!10vy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!10vy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a3297430-6931-4731-afe6-9ee8dd30badb_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:520745,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/212906374?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!10vy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!10vy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!10vy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!10vy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3297430-6931-4731-afe6-9ee8dd30badb_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On May 21, 2026, OpenTelemetry graduated from the Cloud Native Computing Foundation, the observability project with the second-highest project velocity of any CNCF project, trailing only Kubernetes, per the <a href="https://www.cncf.io/announcements/2026/05/21/cloud-native-computing-foundation-announces-opentelemetrys-graduation-solidifying-status-as-the-de-facto-observability-standard/">CNCF&#8217;s own graduation announcement</a>. That milestone is not the story.</p><p>The story is what shipped alongside it. Over the two years leading up to graduation, the project built out generative AI semantic conventions: a standard vocabulary for describing what a model, an agent, or a tool did during a session, as <a href="https://opentelemetry.io/blog/2026/otel-graduates/">OpenTelemetry&#8217;s own account of the milestone</a> describes it. For the first time, agent behavior has a shape that any compliant backend can read the same way. There is no breach in this piece. No CVE, no enforcement action, no incident of any kind. This is a story about infrastructure, and that is exactly why it matters. The infrastructure AI governance depends on is standardizing, and the gaps left inside it are no longer someone else&#8217;s implementation detail. They are the whole argument.</p><h3><strong>What OpenTelemetry Actually Records</strong></h3><p>The new conventions organize an agent run into three span types, <a href="https://securityboulevard.com/2026/08/opentelemetry-and-ai-governance-telemetry-kovrr/">as Kovrr&#8217;s analysis of the standard lays out</a>. A root span records the full, multi-turn agent session. Child spans record each individual model interaction, carrying token counts and the reason generation stopped. A separate span type records tool execution, and that third type was extended during 2026 specifically to cover <a href="http://kiteworks.com/platform/security/mcp-ai-integration/">Model Context Protocol</a> calls, giving agent tool use a portable representation instead of a framework-specific log line buried in someone&#8217;s vendor console.</p><p>That MCP-specific extension is the detail worth sitting with. Before it, what an agent called through MCP, and with what arguments, lived in whatever shape the framework happened to emit. The <a href="http://kiteworks.com/platform/security/mcp-ai-integration/">Model Context Protocol</a> project&#8217;s own maintainers had been wrestling with exactly this gap, <a href="https://github.com/modelcontextprotocol/modelcontextprotocol/discussions/269">proposing OpenTelemetry trace support for MCP</a> precisely because agent-side traces and MCP server-side traces were disconnected from each other. Standardizing that span type means the question of what an agent invoked now has one answer instead of a dozen vendor-specific ones. That is a genuine advance. It is also, on its own, a smaller advance than it sounds.</p><h3><strong>The Governance Deficit This Standard Drops Into</strong></h3><p>Standardized telemetry did not arrive because the industry had gotten ahead of agentic AI. It arrived because the industry is badly behind. The World Economic Forum&#8217;s Global Cybersecurity Outlook 2026 found that 87% of cyber leaders identify AI-related <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerabilities</a> as the fastest-growing cyber risk they face, according to the WEF&#8217;s own report. Kiteworks&#8217; own <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Kiteworks Data Security and Compliance Risk: 2026 Forecast Report</a>, published in December 2025, predicted that 100% of organizations would carry agentic AI on their roadmap in 2026, with fewer than 40% having deployed containment controls to manage it.</p><p>Read that again. Full deployment, minority containment. A standardized way to record what an agent did does not close that gap. It documents it more consistently.</p><h3><strong>Three Things the Trace Will Never Tell You</strong></h3><p>Here is where the Kovrr analysis earns its keep, because it does not oversell the standard. It names three absences, and argues each is a deliberate design boundary rather than an oversight the next release will fix.</p><p>No verdicts. A span records that a model produced an output. It does not record whether that output was hallucinated, unfaithful, toxic, or a policy violation. Evaluation is a separate discipline, deliberately kept out of the telemetry layer.</p><p>No authorization, either. A span carries a service identity and a model provider. It does not carry whether the human on whose behalf an agent acted was actually authorized to touch the specific data the agent reached, and it does not distinguish an agent operating under its own <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credential</a> from one operating under a delegated one. Knowing a call occurred is not the same as knowing it should have occurred.</p><p>And no data sensitivity. Content capture exists for prompts and completions. Nothing in the convention classifies what that content was. Whether a prompt carried regulated health data, financial data, or <a href="http://kiteworks.com/risk-compliance-glossary/cmmc-cui-and-what-it-means/">CUI</a> is a determination applied to the trace afterward, by something else, or by no one at all.</p><p>Stop asking whether your organization has AI observability. Here is the question that actually matters: when the trace shows an agent touched a record, can you produce, on demand, who that agent was acting for and whether that person was cleared to see it?</p><h3><strong>Where the Architecture Has to Pick Up the Slack</strong></h3><p>None of the three gaps above is a flaw in OpenTelemetry. They are a boundary the standard drew on purpose, and Kovrr&#8217;s own framing treats the boundary as correct: a convention that tried to standardize a verdict would have to standardize the policy behind it, and policy differs by organization. That means the second gap, the authorization gap, cannot be solved by waiting for the next OpenTelemetry release. It has to be solved by the architecture the agent and the human both operate inside.</p><p>This is not an incident piece, and I am not going to pretend otherwise to manufacture urgency. There was no breach behind this story. What there is instead is a precise architectural fit, and it deserves to be described precisely rather than oversold. The <a href="https://www.kiteworks.com/platform/security/mcp-ai-integration/">Kiteworks Secure MCP Server</a> enforces per-request <a href="http://kiteworks.com/risk-compliance-glossary/attribute-based-access-control/">attribute-based access control</a> against every AI operation, mirroring the same <a href="http://kiteworks.com/risk-compliance-glossary/role-based-access-control/">role-based</a> and attribute-based rules that already govern human users, and logs each action to a tamper-evident <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> that feeds an organization&#8217;s <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a>. That closes the authorization gap specifically: it is a record not just that an agent called a tool, but that the human identity behind the call was evaluated against policy at the moment of the call, alongside every human who touches the same system. Agents and humans sit inside one governance plane, not two. The Secure MCP Server does not hand you an output-quality verdict, and it does not manufacture a data-sensitivity label your own policy hasn&#8217;t defined. If your <a href="http://kiteworks.com/risk-compliance-glossary/attribute-based-access-control/">attribute-based access control</a> encodes <a href="http://kiteworks.com/secure-file-transfer/data-classification-what-it-is-types-and-best-practices/">data classification</a>, that third gap narrows too. If it does not, it stays open, and no vendor closes it for you.</p><h3><strong>What This Means Now</strong></h3><p><span>&#8226; </span>Pull the trace from your highest-privilege agent workflow and check whether it names the human identity the agent acted for. If it only names a service account, you have the authorization gap in production right now.</p><p><span>&#8226; </span>Ask your platform or observability vendor whether their AI spans already cover the MCP tool-execution extension. If they answer with a roadmap instead of a version number, plan around the gap for the next two quarters.</p><p><span>&#8226; </span>Separately track three things your telemetry will never hand you: an output-quality verdict, an authorization decision, and a data-sensitivity label. Assign an owner to each. None of them are the same owner.</p><p><span>&#8226; </span>If your agents run under a shared service <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credential</a> instead of delegated, revocable ones, fix that before you fix your dashboards. A beautifully instrumented trace built on top of an unauthorized access pattern is still an unauthorized access pattern, just a well-documented one.</p><p>OpenTelemetry gave AI governance a shared way to describe what happened. It was never going to tell you whether it should have.</p>]]></content:encoded></item><item><title><![CDATA[Your AI Assessment Expired the Moment You Signed It.]]></title><description><![CDATA[The model that passed your test in March isn&#8217;t answering prompts the same way today. And in most audit logs, the agent that acted in its place is still wearing a human&#8217;s name.]]></description><link>https://kiteworks.substack.com/p/your-ai-assessment-expired-the-moment</link><guid isPermaLink="false">https://kiteworks.substack.com/p/your-ai-assessment-expired-the-moment</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Wed, 26 Aug 2026 15:01:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ANfG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ANfG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ANfG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!ANfG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!ANfG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!ANfG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ANfG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f62c03a2-b081-4947-996f-32537688b7b5_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:595791,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/212717329?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ANfG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!ANfG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!ANfG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!ANfG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff62c03a2-b081-4947-996f-32537688b7b5_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Consider a security engineer at a mid-size insurer who reruns the same adversarial prompt suite against a customer-service model that cleared testing five months earlier. Same prompts. Same categories. Same environment -- nobody touched the network, the contract, or the guardrail configuration. Four attempts succeed that failed in March.</p><p>That is not a breach. Nobody attacked anything. <a href="https://securityboulevard.com/2026/08/real-time-ai-security-monitoring-explained-kovrr/">Kovrr&#8217;s August 16 analysis</a> makes the harder point: an AI security assessment doesn&#8217;t describe a system, it describes a moment, and the moment closes the day the report gets filed. Here&#8217;s the question that actually matters for anyone who has to sign that report: what exactly are you attesting to when you say a system &#8220;passed&#8221;?</p><h3>What It Actually Is</h3><p>Kovrr names three mechanisms, and only one of them resembles anything in a traditional software audit.</p><p>The first is non-determinism. A prompt injection attempt blocked on the first try can succeed on the fifth, and a single test run is a sample from a distribution, not a measurement of a fixed state. The <a href="https://www.helpnetsecurity.com/2026/08/06/owasp-2026-llm-top-10-released/">OWASP GenAI Security Project&#8217;s 2026 Top 10 for LLM Applications</a>, released ten days before Kovrr&#8217;s piece, ranks Prompt Injection first again, and for a reason that backs this up directly: the flaw is architectural, instructions and data share one channel, and, as the project leads put it, &#8220;the model will be fooled&#8221; no matter how much a team spends trying to prevent it.</p><p>The second is provider-side drift. The vendor revises the model on its own release schedule, and a guardrail validated in March can weaken in April with no change to your prompt, your configuration, or your code.</p><p>The third is retrieval corpus drift. Add one document to a RAG store and you change what the model can say. Add a document containing hidden instructions and you change what it might do -- that&#8217;s indirect prompt injection, and it means the model was never the whole system being tested. The corpus is half the surface, and it&#8217;s the half that changes weekly.</p><p>Read that again: all three failure modes can invalidate a signed-off assessment while nothing in your environment moved. That is not a vendor talking point. It is a structural property of the technology.</p><h3>The Pattern</h3><p>This isn&#8217;t a niche concern confined to chatbots. It&#8217;s what happens when non-human actors multiply faster than the controls built for them.</p><p>Palo Alto Networks&#8217; <a href="https://www.helpnetsecurity.com/2026/05/14/2026-identity-security-landscape-report/">2026 Identity Security Landscape report</a> found organizations now manage 109 machine identities for every human identity, and AI agents already account for a growing share of that number. Companies expect agent growth of 85% over the next 12 months. Most can explain what an agent is for. Far fewer can say what it&#8217;s allowed to touch, when its access gets revoked, or which systems inherit that access by default.</p><p><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-global-threat-report-findings/">CrowdStrike&#8217;s 2026 Global Threat Report</a> supplies the attacker&#8217;s side of the same coin. AI-enabled adversaries increased operations 89% year over year in 2025, and 82% of that year&#8217;s detections were <a href="http://kitworks.com/cybersecurity-risk-management/malware-based-attacks/">malware-free</a> -- meaning intrusions rode valid <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> and trusted identity flows instead of exploits. When the access path itself is the weapon, whose credential is doing the acting stops being a compliance footnote.</p><h3>Why the Math Got Worse</h3><p>Here&#8217;s the compounding factor that makes this different from the last five years of &#8220;patch faster, test more often&#8221; advice. Organizations are deploying agents faster than they&#8217;re deploying the identity controls to tell agents apart from the humans who authorized them.</p><p>The <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Kiteworks Data Security and Compliance Risk: 2026 Forecast Report</a> found 100% of surveyed organizations have agentic AI on their roadmap, but only 37% enforce purpose binding on what those agents can do. Sixty-three percent cannot enforce purpose limitations at all. Sixty percent cannot terminate a misbehaving agent. Fifty-five percent cannot isolate an AI system from the rest of the network.</p><p>Now overlay Kovrr&#8217;s own observation about attribution: &#8220;an agent operating with a human&#8217;s <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> appears in logs as that human unless machine identity is resolved separately, and agent identity is the prerequisite rather than a refinement.&#8221; Put those two data points together and you get a specific, ugly scenario. An agent inherits a service account. It takes an action nobody would authorize a human to take alone. The log says a person did it -- because, as far as the log is concerned, a person did.</p><h3>The Architectural Question</h3><p>None of this means the fix is a better prompt-injection filter or a more frequent penetration test. Those address non-determinism and provider drift, and Kovrr is right that they need to run on a schedule, not just before launch. They do not address attribution. A guardrail that catches a bad prompt still can&#8217;t tell you, after the fact, whether it was Priya or Priya&#8217;s expense-report agent that pulled the file.</p><p>This piece of the problem lives at the data-access layer, not the model layer -- and it&#8217;s worth being precise about scope, because it&#8217;s tempting to oversell it. Resolving machine identity doesn&#8217;t make a model&#8217;s outputs deterministic. It doesn&#8217;t stop a poisoned document from reaching a RAG pipeline. What it does is make sure that when an agent touches a file, the <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> records the agent, not the human whose session it borrowed.</p><p>That&#8217;s the specific gap Kiteworks&#8217; <a href="https://www.kiteworks.com/platform/security/mcp-ai-integration/">Secure MCP Server</a> is built to close: every AI request is authenticated and authorized against <a href="http://kiteworks.com/risk-compliance-glossary/attribute-based-access-control/">attribute-based access controls</a> independently of the human who launched the session, then logged under its own identity in a tamper-evident <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a>. <a href="https://www.kiteworks.com/platform/compliance/compliant-ai/">Kiteworks Compliant AI</a> applies the same principle to programmatic workflows -- RAG pipelines, data extraction jobs, agent-to-agent exchanges. Both sit inside the same Kiteworks Control Plane that governs human and agent access under one policy engine, one <a href="http://kiteworks.com/secure-file-sharing/secure-file-sharing-essential-data-encryption-best-practices/">encryption</a> standard, one <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit log</a>. Humans don&#8217;t lose oversight because an agent is in the loop. The agent&#8217;s actions just stop hiding inside the human&#8217;s identity.</p><p>There&#8217;s no incident behind this argument, and it would be dishonest to pretend otherwise. Nothing in Kovrr&#8217;s piece describes a breach. The fit here is architectural: the attribution gap Kovrr names is exactly the non-human-identity problem this category of tooling exists to close. It is not a claim that any specific product would have stopped anything, because nothing here happened.</p><h3>What This Means Monday Morning</h3><p>Pull your last three AI vendor security attestations and check whether they name a model version, a test date, and an attempt count. If they just say &#8220;passed,&#8221; you&#8217;re holding a photograph, not a monitoring feed.</p><p>Ask your AI vendors how they detect provider-side model revisions, and whether that detection triggers a re-test rather than a release note buried in a changelog.</p><p>Audit your service accounts for agent traffic. If you can&#8217;t separate &#8220;this API key is a scheduled job&#8221; from &#8220;this API key is an agent acting semi-autonomously,&#8221; you have an attribution gap before you have a monitoring gap.</p><p>Put machine identity resolution on the same roadmap line as continuous monitoring, not after it. A perfectly monitored system that still logs agents as humans gives you a detailed record of the wrong actor.</p><p>When your RAG pipeline gets a new source connected, treat it as a production change and give it the review your code changes get. It is one.</p><p>The assessment you signed off on last quarter already expired. The only question left is whether your logs will tell you who acted while you weren&#8217;t looking, or just whose name happened to be on the session.</p>]]></content:encoded></item><item><title><![CDATA[Shadow AI Isn’t a Policy Problem. It’s a $19.5 Million Line Item.]]></title><description><![CDATA[Stop calling it a training gap. Start calling it what your CFO would call it: an unbudgeted liability with a number attached.]]></description><link>https://kiteworks.substack.com/p/shadow-ai-isnt-a-policy-problem-its</link><guid isPermaLink="false">https://kiteworks.substack.com/p/shadow-ai-isnt-a-policy-problem-its</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Tue, 25 Aug 2026 15:03:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vzAy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vzAy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vzAy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!vzAy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!vzAy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!vzAy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vzAy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:578629,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/212567887?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vzAy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!vzAy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!vzAy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!vzAy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36fcd2ce-e588-41c9-8b85-634e930a0605_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Picture a typical Tuesday morning. Someone on your finance team pastes a client contract into a free chatbot to get a faster summary. Someone in engineering feeds a repo&#8217;s worth of source code into an AI coding assistant to debug a release. Someone in HR uploads a spreadsheet of comp data to draft a policy memo. None of them think they did anything wrong. None of them will mention it to you. And none of it shows up on a single security dashboard you own.</p><p>That is the scene playing out inside most enterprises right now, and the instinct in security leadership is still to respond with a training module. That instinct is the problem. The <a href="https://ponemon.dtex.ai/">2026 Cost of Insider Risks Global Report</a> puts a number on what happens when you keep treating an architecture failure as a behavior failure: average annual insider risk cost has reached $19.5 million per organization, and <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> is now the leading driver of negligent insider incidents -- employees routinely moving confidential documents, source code, and strategy through AI channels nobody approved.</p><p>Nineteen and a half million dollars. Read that again. That&#8217;s not a training gap. That&#8217;s a line item finance doesn&#8217;t know it&#8217;s carrying.</p><p>Here&#8217;s the thesis: shadow AI stopped being a policy problem the moment it became a recurring, quantifiable cost. It belongs on the same reporting line as fraud losses and breach remediation -- not buried in a security awareness budget.</p><h3>What It Actually Is</h3><p>The 2026 Data Security and Compliance Risk Report found that 65% of organizations discovered employees using unapproved AI tools with organizational data in the past 12 months. Sixteen percent discover it monthly or more. Twenty-eight percent discover it quarterly. This is not a rare lapse. It is a standing operational condition, discovered on a schedule, the way you&#8217;d discover a recurring vendor invoice.</p><p>And the data moving through those tools is not incidental. Among organizations using employee-facing AI chatbots, 36% route customer and client data through them. 33% route IT <a href="http://kiteworks.com/risk-compliance-glossary/credential-stuffing/">credentials</a> and access requests. 31% route employee personal and HR data. 30% route financial data. None of those are categories any organization intends to hand to an AI vendor. They are categories employees hand over anyway, because the tool is faster than the approved workflow -- and because nothing in the environment stops the request.</p><h3>The Market Reality: Bans Are Gone, Controls Never Arrived</h3><p>For a while, the default corporate response to this was prohibition. That response is evaporating. <a href="https://www.cisco.com/c/en/us/about/trust-center/data-privacy-benchmark-study.html">Cisco&#8217;s 2026 Data and Privacy Benchmark Study</a> found that outright bans on AI tool usage dropped from 28% of organizations in 2025 to 7% in 2026 -- a 21-point decline in a single year. Enterprise AI usage more than doubled over the same period, with 62% of workers now using AI at work.</p><p>Here is the part that should bother a CFO more than a CISO: that 21-point drop in bans did not come with a corresponding rise in technical controls to replace them. Organizations removed the barrier. They left the gap open. That is not a governance evolution. That is a governance vacancy, and vacancies compound.</p><h3>Why the Math Got Worse</h3><p>Twenty-six percent of organizations experienced sensitive data exposure through an AI tool in the past 12 months, per the same report. Run that against the discovery numbers and a pattern falls out: <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> use is nearly universal, exposure incidents are common, and the organizations catching the most of it are the ones with the best detection -- not the worst problem. North America reports the highest frequent shadow AI discovery rate, 24% monthly or more, and the highest overall AI incident rate, 84%. The report is explicit that detection capability, not shadow AI prevalence, drives the regional spread. Regions reporting less shadow AI are not cleaner. They are blinder. A lower discovery rate is not good news. It&#8217;s a visibility gap wearing a good-news costume, and it means the true exposure in weaker-detection regions is very likely higher than what shows up in any survey.</p><p>That reframes the entire risk conversation. If detection quality is the variable, the $19.5 million figure is not a ceiling. It&#8217;s a floor for organizations with above-average visibility, and an underestimate for everyone else.</p><h3>The Architectural Question</h3><p>Stop asking how to get employees to behave better. Here is the question that actually matters: where in your stack is sensitive data structurally prevented from leaving through an AI channel nobody approved? Only 28% of organizations have AI-specific <a href="http://kiteworks.com/risk-compliance-glossary/data-loss-prevention-dlp/">data loss prevention</a> deployed -- the control that actually blocks sensitive data from reaching an unapproved AI tool at the point of transmission, rather than documenting the violation after it already happened. Only 27% have purpose binding in place, restricting what an AI system or agent is even permitted to touch. Fewer than half of organizations that discovered <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> went on to deploy technical controls to prevent it from recurring. The most common response instead was updated policy guidance -- a behavioral fix bolted onto an architectural hole. Thirty-six percent name workforce training as a top investment priority: the most commonly planned response to a problem that training cannot structurally solve, because the gap it&#8217;s meant to close sits in the network, not in the employee&#8217;s judgment.</p><p>Call it what it is: governance theater. Policies get rewritten. Nothing in the network actually stops the data.</p><p>This is where the fix has to be architectural rather than administrative. You cannot train your way past a missing control layer. What closes this gap is a single governing layer that applies consistent, technically enforced policy across every channel where sensitive data can leave the building -- email, file transfer, web forms, APIs, and yes, the AI chatbot someone just opened in another tab -- so &#8220;unapproved&#8221; becomes a state the system enforces, not a state the handbook describes. A hardened, single-tenant architecture with unified policy enforcement and audit-quality logging turns &#8220;we told employees not to&#8221; into &#8220;the data literally could not leave through that channel.&#8221; That governance applies the same way whether a human or an AI agent is the one making the request -- one policy layer, not a separate memo for each. That distinction is the entire difference between a $19.5 million line item and a line item that shrinks every quarter.</p><h3>What to Do Monday Morning</h3><p><span>1. </span>Pull your last four quarters of <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">shadow AI</a> discovery data and price it the way finance would -- as a recurring loss category, not an incident log.</p><p><span>2. </span>Ask your AI governance owner one question: what percentage of sensitive data channels have technical enforcement versus policy language only. If you don&#8217;t have an answer, you don&#8217;t have a control. You have a memo.</p><p><span>3. </span>Audit whether your organization dropped a usage ban in the last 18 months without replacing it with a technical control. If so, you have a documented, dated governance gap -- useful information for your risk register and uncomfortable information for your board deck.</p><p><span>4. </span>Stop budgeting training as your primary AI data security investment. Budget detection and enforcement instead, and let training support the control layer rather than substitute for it.</p><p><span>5. </span>Put the dollar figure in front of the board before the auditors put it in front of you.</p><p>Training doesn&#8217;t show up on a balance sheet. A $19.5 million exposure does. Start reporting it like one.</p><p><em>Read the full findings in the <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-data-security-compliance-risk-report.pdf">2026 Data Security and Compliance Risk Report</a>.</em></p>]]></content:encoded></item><item><title><![CDATA[Vague AI Claims Cost You 8 Points of Growth.]]></title><description><![CDATA[The market started pricing the difference between AI you can prove and AI you can only describe. Most compliance programs still can&#8217;t produce the proof.]]></description><link>https://kiteworks.substack.com/p/vague-ai-claims-cost-you-8-points</link><guid isPermaLink="false">https://kiteworks.substack.com/p/vague-ai-claims-cost-you-8-points</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Mon, 24 Aug 2026 15:03:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Yrts!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Yrts!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Yrts!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!Yrts!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!Yrts!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!Yrts!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Yrts!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:566178,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/212164504?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Yrts!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!Yrts!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!Yrts!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!Yrts!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F388ee14a-2178-44d4-a6c0-9fce56377bb5_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On March 18, 2024, the SEC fined two investment advisers a combined $400,000 for lying about the AI inside their products. Delphia claimed it used machine learning to analyze client data it never actually collected. Global Predictions called itself the &#8220;first regulated AI financial advisor&#8221; and was neither regulated in that specific way nor building the AI it advertised. <a href="https://www.sec.gov/newsroom/press-releases/2024-36">The SEC&#8217;s own release</a> is almost bored in its phrasing: false and misleading statements, Section 206 violations, penalties, done.</p><p>That is not really a story about two small advisers getting caught puffing. It&#8217;s a preview.</p><p>A working paper out of Carnegie Mellon&#8217;s AI Capstone Program, run with AI-adoption analytics firm Larridin, just put a number on exactly what that gap is worth across the market. <a href="https://48003527.fs1.hubspotusercontent-na2.net/hubfs/48003527/CMU-Larridin%20AI-Company%20Performance%2020270811.pdf">The study</a> scored roughly 500 large U.S. public companies on how concretely they describe their AI systems in 10-K filings, then checked that score against what actually happened to their revenue. Here&#8217;s the whole game: companies that named specific, deployed AI systems with quantified results grew about 8 percentage points faster, year over year, than companies that talked about AI in the abstract. Holding sector, size, and prior growth momentum constant.</p><p>Read that again. Eight points. Not from spending more on AI. Not from hiring more AI engineers. From being specific.</p><h3>The study that priced specificity</h3><p>The researchers &#8211; Yixiao Li, Siru Tao, Xin Xu, and Hanzhe Hong &#8211; built three independent signal sets: Larridin&#8217;s own AI Transformation Tracker scores for 562 companies, an LLM-extraction pipeline that scored 478 companies&#8217; 10-K filings on investment intensity, &#8220;narrative concreteness,&#8221; and risk-disclosure depth, and a hiring-intensity measure built from 30,861 classified job postings across 536 companies. Every non-null disclosure score had to cite a verbatim passage from the filing &#8211; no score without a receipt. In an audit, 87 to 90% of those citations checked out against the source text.</p><p>Narrative concreteness &#8211; deployed, named use cases with measurable outcomes, not &#8220;AI-powered&#8221; marketing copy &#8211; was the only signal that survived every control they threw at it: sector, company size, and pre-existing growth momentum. Coefficient of 0.080, p = 0.009. Everything else in the study washed out, attenuated, or never mattered in the first place.</p><h3>Every other AI metric washed out</h3><p>AI investment intensity looked promising until the researchers controlled for company size, at which point it stopped being significant (p = 0.14). The AI-hiring signal, built from real job-posting data, showed no relationship with performance at all &#8211; and the researchers admit their hiring snapshots were collected after the financial quarter they were tested against, so it was never a fair predictive test to begin with. Risk-disclosure depth, the closest thing to an &#8220;AI policy&#8221; signal in the study, had almost no discriminating power because 75% of the companies sampled landed at the identical score. Boilerplate <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">AI-risk</a> language has become exactly that: boilerplate.</p><p>This is not an isolated finding. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027">Gartner predicted in June 2025</a> that more than 40% of agentic AI projects will be canceled by the end of 2027, citing escalating costs, unclear business value, and &#8220;agent washing&#8221; &#8211; chatbots relabeled as agents for the pitch deck. MIT&#8217;s Project NANDA went further: its 2025 State of AI in Business report, based on an analysis of 300 public AI deployments plus 52 executive interviews and a survey of 153 business leaders, found that <a href="https://www.forbes.com/sites/jasonsnyder/2025/08/26/mit-finds-95-of-genai-pilots-fail-because-companies-avoid-friction/">95% of generative AI pilots produce no measurable P&amp;L impact</a> despite $30 to $40 billion in enterprise investment. Three independent research efforts, three different methodologies, one converging answer: activity is not evidence, and the market &#8211; and now the researchers &#8211; have started telling activity and evidence apart.</p><h3>Why the math got worse this year</h3><p>Here&#8217;s where it gets uncomfortable. The CMU-Larridin effect was strongest, not among AI-native software companies where deployment is easy to verify, but inside the 285-company &#8220;physical-asset-heavy, late adopter&#8221; bucket &#8211; manufacturers, retailers, industrials &#8211; where AI claims are cheapest to make and hardest to check (n = 214, p = 0.025). That is precisely where most of the enterprise market sits.</p><p>And the SEC isn&#8217;t finished. AI-washing enforcement that started with two small advisers in 2024 has continued into 2026, and it maps onto the same variable the CMU-Larridin researchers isolated almost exactly: can you show your work? A regulator asking &#8220;prove it&#8221; and a market pricing &#8220;prove it&#8221; into your growth rate are the same test, arriving from two directions at once.</p><h3>The architectural question</h3><p>Stop asking whether your AI story sounds good. Here is the question that actually matters: if a regulator, an acquirer, or a reporter asked you tomorrow to produce the evidence behind your last AI claim &#8211; the system, the data it touched, who authorized that, and what happened &#8211; could you produce it by Friday, or would you be reconstructing it from memory and Slack threads?</p><p>Most organizations can&#8217;t. <a href="https://www.kiteworks.com/cybersecurity-risk-management/ai-governance-gap-widens-2026/">Kiteworks&#8217; 2026 Data Security and Compliance Risk: Annual Survey Report</a> found that 33% of organizations have no evidence-quality <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> at all for their AI systems &#8211; and those organizations run 20 to 32 points behind on every other AI governance maturity metric measured. Fifty-one percent already have agents running in production. Sixty-three percent of those same organizations cannot enforce a purpose limitation on what that agent is allowed to do. Sixty percent cannot kill a misbehaving agent. The gap is not AI ambition. It&#8217;s proof.</p><p>This is an architecture problem, not a policy problem. A committee, a written AI policy, and a training deck do not generate evidence &#8211; they generate paper. What generates evidence is a system that logs, at the point of access, which identity (human or agent, same category) touched which data, under what authorization, and what it did next, in a format that survives being asked about eighteen months later. That is the design premise behind platforms like Kiteworks, which routes AI and human access to sensitive data through one policy engine and one <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> rather than a dozen disconnected logs &#8211; not because Kiteworks invented the idea of evidence, but because &#8220;prove it later&#8221; has to be built in at the point data moves, not bolted on after an inquiry lands.</p><h3>What to do Monday morning</h3><p><span>1. </span>Pull your last public AI claim &#8211; investor update, press release, sales deck. Does it name a specific system and a specific, quantified result? If not, that&#8217;s the same gap the SEC just fined two firms $400,000 over.</p><p><span>2. </span>Ask whoever owns your AI or agent deployments to produce, this week, a log of every access to sensitive data by an AI system in the last 30 days &#8211; who or what accessed it, under what authorization. Time how long it takes. That&#8217;s your evidence-readiness number.</p><p><span>3. </span>Stop scoring internal AI maturity by spend, vendor count, or headcount. None of the three predicted anything in the CMU-Larridin study. Score it by named use cases with quantified outcomes instead.</p><p><span>4. </span>Compare your <a href="http://kiteworks.com/cybersecurity-risk-management/zero-trust-generative-ai/">AI-risk</a> disclosure language to a competitor&#8217;s. If a reasonable reader couldn&#8217;t tell them apart, rewrite yours &#8211; generic language no longer reads as maturity, it reads as absence.</p><p><span>5. </span>Map one production AI workflow end to end: identity, data, purpose, authorization, action, destination, jurisdiction. If you can&#8217;t fill in all seven, you&#8217;ve found your actual risk, not the one in your slide deck.</p><p>The market has already started pricing the difference between AI you can prove and AI you can only describe. Regulators are just getting started doing the same thing.</p>]]></content:encoded></item><item><title><![CDATA[We Forecast These AI Governance Gaps. They Got Worse.]]></title><description><![CDATA[&#8220;The Forecast was correct about the direction. It was optimistic about the scale.&#8221;]]></description><link>https://kiteworks.substack.com/p/we-forecast-these-ai-governance-gaps</link><guid isPermaLink="false">https://kiteworks.substack.com/p/we-forecast-these-ai-governance-gaps</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Fri, 21 Aug 2026 15:00:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!q4Xh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q4Xh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q4Xh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!q4Xh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!q4Xh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!q4Xh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q4Xh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:375791,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/212046630?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!q4Xh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!q4Xh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!q4Xh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!q4Xh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F83267a66-7dff-4ba2-9346-85ea0e7f75d2_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That line is not my summary. It is the verdict stated in the <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">2026 Data Security and Compliance Risk Report</a> about its own predecessor. In December 2025, Kiteworks published a Forecast Report built on 225 respondents and fifteen specific predictions about where AI data governance would stand in 2026. It predicted 100% of organizations would have agentic AI on the roadmap, with fewer than 40% holding any containment control capable of managing it. Five months later, the Annual Survey went back into the field with 459 respondents and measured what actually happened: 80% experienced at least one security incident of any type in the past twelve months.</p><p>I&#8217;ve read plenty of forecast-versus-reality reports over the years. Almost all of them find the forecast was too gloomy, because forecasts of this kind tend to assume the worst and reality lands somewhere more forgiving. Not this one. That is not a forecast that missed high. That is a forecast that undersold the exposure. Read that again: the report built to warn the industry turned out to be the optimistic version of events.</p><h3>The verdict nobody at Kiteworks wanted to write</h3><p>Every one of those fifteen predictions assumed some closing of the gap, because that&#8217;s what forecasts of this kind assume: organizations see the problem coming, budgets get allocated, controls get deployed, the number improves by the time anyone checks back. Six months is enough time to fix a checklist item. It is not enough time to fix an architecture. The Annual Survey checked, and almost nothing improved. Several things got measurably worse.</p><p>Here&#8217;s the whole game: this piece isn&#8217;t about a report being wrong. It&#8217;s about an industry that heard the warning, agreed with the direction, and still didn&#8217;t move fast enough to beat it.</p><h3>Every line item moved the wrong direction</h3><p>Look at the specific controls the Forecast flagged as the ones to watch, December against July:</p><p>AI kill switches: 60% lacking, then 70% lacking. Behavioral monitoring for AI systems: 60% lacking, then 69% &#8211; the detection deficit widened instead of closing, which is the opposite of what a maturing control environment is supposed to produce. Tamper-evident <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trails</a>: 33% lacking in December, 67% lacking by July. Purpose binding &#8211; the control that restricts an AI agent to the task and data scope it was actually authorized for &#8211; 63% absent, then 74% absent.</p><p>One metric didn&#8217;t move at all, and that&#8217;s the one that should worry you most: 73% of organizations couldn&#8217;t produce a complete AI data access audit record within one business day in the Forecast. The Annual Survey found the same 73% unable to do it six months later. Flat. Zero progress on a control that DORA, NIS2, and the EU AI Act already expect to be operational.</p><p>Call it what it is: an optimism tax. The industry priced in improvement that never arrived, and now the gap is bigger than the number anyone budgeted against.</p><h3>The boardroom never showed up</h3><p>The strongest correlation in the entire Forecast Report was between board-level AI governance engagement and everything else measured: organizations where the board carried a standing AI data governance agenda item scored 26 to 28 points higher on AI maturity than organizations where it didn&#8217;t. The Forecast measured 54% of boards with no such agenda item. The Annual Survey measured the same 54%. Unchanged.</p><p>That&#8217;s a line item on a meeting agenda, not a budget request. Six months passed, and it still didn&#8217;t get added.</p><h3>The gateway problem nobody closed</h3><p>The Forecast identified centralized AI data gateways as the control that determines everything downstream of it &#8211; classification, purpose binding, audit capture, kill switch enforcement, all easier or harder depending on whether AI traffic runs through one governed point or scatters across a dozen ungoverned ones. It found 57% of organizations without one. The Annual Survey confirms the same picture from the other side: only 43% have achieved centralized AI gateway control. Same gap, six months apart, different survey.</p><p>Third-party AI vendor risk tells the same story with a different number attached. The Forecast found 89% of organizations had never practiced <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a> with an AI vendor partner. The Annual Survey found 27% still haven&#8217;t even evaluated or technically verified whether their AI vendors train models on customer data. More than a quarter of organizations are handing sensitive data to AI vendors on trust alone, with no <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a> plan behind it if that trust turns out to be misplaced.</p><p>And Government, which the Forecast called a generation behind &#8211; 90% lacking centralized AI gateways, 76% missing kill switches, 90% missing purpose binding &#8211; still posts the lowest maturity scores of any sector six months later. Federal Government and Defense Contractors haven&#8217;t moved off the bottom.</p><p>Here&#8217;s where it gets uncomfortable: none of this is a patching problem. You cannot bolt a kill switch onto an AI pipeline the week before an audit and call the 74% purpose binding gap solved. What the data describes is an architecture problem &#8211; AI data access running through as many paths as there are tools, with no single point where policy, logging, and containment get enforced consistently. That&#8217;s the premise behind the Kiteworks Control Plane, which I work on: one policy engine, running on single-tenant infrastructure, generating evidence-quality <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trails</a> for every channel sensitive data moves through and every identity that touches it &#8211; human or agent, governed the same way, under the same plane. A gateway alone doesn&#8217;t fix a 54% board-engagement problem. But you cannot fix the board problem, the purpose-binding problem, and the audit-trail problem separately when they all run through the same ungoverned pipes.</p><h3>What to do Monday morning</h3><p>The Forecast told you what to fix in December. Most organizations didn&#8217;t. If you&#8217;re deciding where to start now:</p><p><span>1. </span>Put AI data governance on the board agenda as a standing item, not a slide in the annual security review. The 26-to-28-point maturity gap tied to this habit hasn&#8217;t closed since December, and it costs nothing to fix.</p><p><span>2. </span>Test your kill switch. 23% of organizations with AI in production have never tested theirs. An untested kill switch is a hope, not a control.</p><p><span>3. </span>Get purpose binding in place before you add another AI use case. 74% absent means most of you are stacking capability on top of a control that doesn&#8217;t exist yet.</p><p><span>4. </span>Route AI traffic through a centralized gateway before you audit anything else. Fragmented paths are why 67% still lack tamper-evident <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trails</a>.</p><p><span>5. </span>Verify, in writing, whether every AI vendor touching your data trains models on it. 27% of organizations still don&#8217;t know the answer to their own question.</p><p>Five months ago, we told you where this was headed. Nobody disputed the direction. The industry just didn&#8217;t move fast enough to beat it.</p><p><em>Read the full findings in the <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-data-security-compliance-risk-report.pdf">2026 Data Security and Compliance Risk Report</a>.</em></p><p></p>]]></content:encoded></item><item><title><![CDATA[83% of You Can’t Produce an AI Audit Record in an Hour. The EU AI Act Isn’t Waiting.]]></title><description><![CDATA[Your policy document says you&#8217;re compliant. Your logging infrastructure says otherwise, and the logging infrastructure is what auditors read.]]></description><link>https://kiteworks.substack.com/p/83-of-you-cant-produce-an-ai-audit</link><guid isPermaLink="false">https://kiteworks.substack.com/p/83-of-you-cant-produce-an-ai-audit</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Thu, 20 Aug 2026 15:01:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!oZpM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oZpM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oZpM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!oZpM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!oZpM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!oZpM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oZpM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:544835,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/211734302?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oZpM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!oZpM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!oZpM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!oZpM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F54efcbc8-9b44-4383-b766-63d095f5a760_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Picture the request. A regulator, an auditor, or a customer&#8217;s security team sends a one-line email: produce the complete AI data access audit record for the last quarter, by end of day. Not next sprint. Not &#8220;we&#8217;ll pull it together for the review.&#8221; Today.</p><p>Here&#8217;s what actually happens next, according to the 2026 Data Security and Compliance Risk Report: 83% of organizations cannot produce that record within one hour. Half cannot produce it within one business day. Ten percent cannot produce it at all &#8211; their logging infrastructure isn&#8217;t built to reconstruct what an AI system touched, no matter how long you give them.</p><p>Read that again. Ten percent of organizations, asked to show what their AI systems accessed, have no answer. Not a slow answer. No answer.</p><p>That&#8217;s the finding everyone should be arguing about, and almost nobody is. Instead, the industry conversation about AI governance still runs on model risk, bias audits, and responsible-AI charters &#8211; worthy topics, wrong emergency. The emergency is that most audit infrastructure was engineered for a world where you had days to respond to a request for evidence. The <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689">EU AI Act</a>, <a href="https://www.iso.org/standard/81230.html">ISO/IEC 42001</a>, and <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554">DORA</a> were built for a world where you have hours. That gap is not a future risk sitting on a roadmap somewhere. It&#8217;s the compliance posture you have right now, today, while you read this.</p><h3>The One-Hour Test Nobody Passes</h3><p>Only 17% of organizations can produce a complete AI audit record within one hour from existing dashboards, according to the report. Flip that number over and sit with it: 83% would fail if the request landed this afternoon.</p><p>This isn&#8217;t a story about organizations lacking a policy. Every company in this survey has an AI governance policy. Every company has an acceptable use document somewhere in a SharePoint folder that nobody has opened since the day it was approved. I have read a stack of these policies over the years. Not one of them generates a log.</p><p>The failure here is not documentation. It&#8217;s plumbing &#8211; whether the systems that actually touch AI data can produce a defensible, timestamped, complete record of what happened, to whom, and when. Fifty percent can&#8217;t do it in a day. Ten percent can&#8217;t do it at all. The policy document was never the control. It was the alibi.</p><h3>Compliance Consequences Are Already Here, Not Coming</h3><p>Sixty-three percent of organizations experienced at least one compliance consequence in the past 12 months, per the report &#8211; an audit finding, a required remediation plan, a board escalation, a contractual penalty, or a formal regulatory investigation. That is not a forecast about 2027. That is what already happened to two-thirds of the organizations surveyed, in the twelve months behind us.</p><p>And yet 7% of organizations have taken no action whatsoever on AI-specific regulatory requirements. None. Zero controls, zero governance changes, in a year when 63% of their peers got hit with a consequence severe enough to reach a board or a regulator.</p><p>The number that should worry a CISO more than either of the ones above: 61% of respondents rank AI-specific regulatory requirements in their top three compliance challenges, and 25% rank it as the single biggest challenge they face &#8211; more than any other item on the list, ahead of <a href="http://kiteworks.com/risk-compliance-glossary/gdpr/">GDPR</a>, ahead of <a href="http://kiteworks.com/risk-compliance-glossary/pci-dss/">PCI DSS</a>, ahead of everything. Organizations know this is the hard problem. They rank it first. And they still can&#8217;t produce the record when asked.</p><h3>Why &#8220;We Have a Policy&#8221; Doesn&#8217;t Survive Contact With a Regulator</h3><p>ISO/IEC 42001 compliance is required for 40% of respondents in this survey. The <a href="http://kiteworks.com/risk-compliance-glossary/eu-ai-act/">EU AI Act</a> imposes transparency, logging, and human oversight obligations that are enforceable now for high-risk system categories &#8211; not pending, not phased in on some horizon slide, active. DORA&#8217;s operational resilience obligations require financial entities to produce audit-quality evidence on short notice, and &#8220;short notice&#8221; in a regulatory context does not mean next quarter.</p><p>Here&#8217;s the whole game: an organization that cannot produce an AI data access record within one business day is not compliant with these frameworks&#8217; audit obligations, regardless of what the policy document says. A binder full of governance language does not satisfy an auditor asking for a system-generated, timestamped access record from three weeks ago. Only one of those things is evidence. The other is homework you did to feel better.</p><p>And even where records exist, they may not survive scrutiny. Only 33% of organizations have tamper-evident <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trails</a> &#8211; the specific evidence type investigators and auditors examine to confirm records haven&#8217;t been altered after the fact. The other 67% are exposed on any audit that requires evidence integrity, which is to say, any audit that matters. You can produce a log. Can you prove nobody touched it afterward? Two-thirds of you cannot.</p><h3>The Architectural Question You&#8217;re Not Asking</h3><p>The instinct here is to solve this the way security teams solve most gaps: add a dashboard, write a script that pulls logs from three systems into a spreadsheet before the auditor arrives. That approach is exactly what produced this problem. Only 40% of organizations apply a consistent evidence approach across all required compliance frameworks, per the report &#8211; meaning most are maintaining separate, ad hoc evidence trails for <a href="http://kiteworks.com/risk-compliance-glossary/gdpr/">GDPR</a>, the <a href="http://kiteworks.com/risk-compliance-glossary/eu-ai-act/">EU AI Act</a>, ISO 27001:2022, and <a href="http://kiteworks.com/risk-compliance-glossary/dora/">DORA</a> simultaneously, reconciled by hand when someone asks.</p><p>That doesn&#8217;t scale to an hour-long deadline. It barely scales to a day-long one.</p><p>The architectural alternative is a single control plane that governs and logs data access, AI included, at the point of exchange rather than after the fact, across email, <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer/">managed file transfer</a>, <a href="http://kiteworks.com/risk-compliance-glossary/sftp/">SFTP</a>, web forms, and API traffic alike. Kiteworks&#8217; approach centers on exactly this premise: a hardened, single-tenant architecture that generates evidence-quality, tamper-evident <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trails</a> as a byproduct of how data moves, not as a report someone assembles under deadline pressure. That same policy engine, the same audit trail, and the same evidence standard apply whether the identity accessing the data is a human employee or an AI agent acting on that employee&#8217;s behalf. An agent&#8217;s access produces the same defensible record a human&#8217;s does. Neither operates on the honor system.</p><p>That&#8217;s the difference between &#8220;we can eventually reconstruct what happened&#8221; and &#8220;here is the record, timestamped and unaltered, right now.&#8221; One of those satisfies <a href="http://kiteworks.com/risk-compliance-glossary/dora/">DORA</a> Article 19. The other satisfies nobody but yourself.</p><h3>What This Means Monday Morning</h3><p><span>1. </span>Run the test yourself before a regulator does. Ask your team to produce a complete AI data access audit record right now, today, and time how long it actually takes.</p><p><span>2. </span>Check whether your <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trails</a> are tamper-evident, not just present. A log that can be edited after the fact is not evidence &#8211; it&#8217;s a story.</p><p><span>3. </span>Map your evidence approach against every framework in scope simultaneously &#8211; ISO 27001:2022, <a href="http://kiteworks.com/risk-compliance-glossary/gdpr/">GDPR</a>, <a href="http://kiteworks.com/risk-compliance-glossary/eu-ai-act/">EU AI Act</a>, <a href="http://kiteworks.com/risk-compliance-glossary/dora/">DORA</a> if applicable &#8211; and find out if you&#8217;re running one consistent evidence model or four incompatible ones stitched together by hand.</p><p><span>4. </span>Assign ownership of AI audit readiness to a specific person with a specific deadline, not to &#8220;compliance&#8221; as a department.</p><p><span>5. </span>Stop treating the policy document as the control. It never was. The system that produces the record on demand is the control.</p><p>The EU AI Act doesn&#8217;t care that your policy document is thorough. Neither does DORA. Neither does the auditor who emails you at 9 a.m. asking for the record by noon. The only question that matters is whether you can produce it, and right now, most of you cannot.</p><p><em>Read the full findings in the<a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-data-security-compliance-risk-report.pdf"> 2026 Data Security and Compliance Risk Report</a>.</em></p>]]></content:encoded></item><item><title><![CDATA[Meet the DSCRI: The One Number That Proves You Can’t Buy Your Way Out of the AI Governance Gap]]></title><description><![CDATA[A composite metric just told 459 organizations that their security budget was solving the wrong equation.]]></description><link>https://kiteworks.substack.com/p/meet-the-dscri-the-one-number-that</link><guid isPermaLink="false">https://kiteworks.substack.com/p/meet-the-dscri-the-one-number-that</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Wed, 19 Aug 2026 15:03:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5RWj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5RWj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5RWj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!5RWj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!5RWj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!5RWj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5RWj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:530735,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/211599318?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5RWj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!5RWj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!5RWj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!5RWj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F17a1afe5-6d92-4b82-b1a4-77b7e35742a2_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>You know the DSMS number by heart even if you&#8217;ve never heard the acronym. Eleven controls &#8211; <a href="http://kiteworks.com/secure-file-sharing/public-vs-private-key-encryption/">encryption</a>, <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer">managed file transfer</a>, <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a> integration, kill switches, the usual checklist. Your team has deployed four, maybe five of them. You feel reasonably good about that on a Tuesday. Then the 2026 Data Security and Compliance Risk Report hands you a new metric, the Data Security and Compliance Readiness Index, and your reasonably-good Tuesday gets worse.</p><p>Here&#8217;s the whole game: DSCRI is not another maturity score to stack on the pile. It&#8217;s a multiplication problem. And multiplication problems don&#8217;t forgive a zero anywhere in the equation.</p><h3>What It Actually Is</h3><p>The formula: DSCRI = DSMS &#215; (AIGMS/100). Your Data Security Maturity Score &#8211; built from those 11 binary controls, normalized 0-100 &#8211; gets scaled by the fraction of AI Governance Maturity Score capabilities you&#8217;ve deployed. AIGMS measures 19 binary AI-specific governance capabilities: purpose binding, behavioral monitoring, AI-specific <a href="http://kiteworks.com/risk-compliance-glossary/data-loss-prevention-dlp/">DLP</a>, <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> generation. Also normalized 0-100.</p><p>The survey mean DSMS is 39. The survey mean AIGMS is 35. Run the multiplication and the mean DSCRI lands at 16.2, with a median of 11.5. Half the organizations in this survey score below 12 out of 100 on organizational AI readiness. That&#8217;s not a rounding error in an obscure sub-metric. That&#8217;s the headline number a 459-organization sample produced when security maturity and AI governance maturity were forced to answer for each other simultaneously.</p><p>Here&#8217;s the part that makes the number bite: it&#8217;s multiplicative, not additive. An organization with a DSMS of 70 and an AIGMS of 20 doesn&#8217;t get credit for the 70. It gets a DSCRI of 14 &#8211; lower than an organization running a modest DSMS of 40 paired with an AIGMS of 45, which scores 18. Excellence in one dimension, unmatched in the other, gets discounted almost to nothing. That&#8217;s the design. It&#8217;s supposed to hurt.</p><h3>The Market Reality</h3><p>Only 19 respondents &#8211; 4% of the sample &#8211; broke the DSCRI midpoint of 50, and doing so required both DSMS and AIGMS to exceed 70 at the same time. Six respondents, barely 1%, cleared 70. The single highest scorer in the entire survey hit 84: a perfect DSMS of 100 paired with an AIGMS of 84, meaning 16 of 19 AI governance capabilities actually deployed, not planned, not budgeted &#8211; deployed.</p><p>Break it down by DSMS tier and the curve stops being gentle. Tier 1 Nascent organizations average a DSCRI of 2.0. Tier 2 Developing, 10.8. Tier 3 Established, 33.4. Tier 4 Advanced, 65.9. That&#8217;s roughly a 33-fold gap between the bottom tier and the top, and it isn&#8217;t linear &#8211; it compounds, because moving up a security tier only pays off in DSCRI terms if AI governance is climbing alongside it.</p><p>And the consequences aren&#8217;t theoretical. 74% of organizations in the survey experienced at least one general security incident. Among the 64% that had deployed AI, 64% experienced an AI-specific incident. Combine the two and 80% experienced at least one incident of either kind, with 63% facing a compliance consequence as a result. A DSCRI in the teens is what an incident rate like that looks like when you convert it into a single number.</p><h3>Why the Math Got Worse</h3><p>Here&#8217;s the part that should bother you more than the raw score does. At the survey mean DSMS of 39, raising AIGMS from 35 to 60 &#8211; deploying more of those 19 AI-specific capabilities &#8211; adds roughly 10 points to your DSCRI. Raising DSMS from 39 to 55 instead, bolting on four more general security controls while AIGMS sits untouched at 35, adds fewer than 6 points.</p><p>Read that again. It inverts the instinct every security budget in this survey seems to be running on. At current baselines, a dollar spent on AI governance returns more composite readiness than a dollar spent on general security controls. Not because general controls don&#8217;t matter. Because AI governance is the scarcer resource. You&#8217;re maxed out on the returns available from the side of the ledger everyone already knows how to fund. The multiplication is telling you where the marginal dollar actually works.</p><p>Most security roadmaps I see are still built almost exclusively around the DSMS side: more <a href="http://kiteworks.com/secure-file-sharing/public-vs-private-key-encryption/">encryption</a>, better SIEM tuning, another kill switch. Call it what it is. Governance debt &#8211; the AI capabilities the org keeps deferring while the general-security backlog gets funded first. All defensible on its own terms. None of it moves the number that&#8217;s actually predicting incident exposure, because the AI governance factor in that equation is sitting at 35 out of 100 and dragging everything above it down with it.</p><h3>The Architectural Question</h3><p>This is where the tactical response runs out of road. You cannot patch your way to a higher DSCRI by adding a twelfth control to an 11-control framework. The gap is architectural: most organizations have general-purpose security tooling that was never built to answer AI-specific questions &#8211; what a model touched, what an agent was authorized to do with a file, whether an inference request left an evidence-quality trail behind it.</p><p>That&#8217;s the premise behind the Kiteworks Control Plane &#8211; worth naming here, not as the fix, but as one example of what an architecture built for this problem actually looks like. A unified policy engine that governs data access, use, and exchange across email, <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer/">MFT</a>, <a href="http://kiteworks.com/risk-compliance-glossary/sftp/">SFTP</a>, web forms, and APIs &#8211; for humans and AI agents alike, under the same rules, rather than a separate bolt-on for whichever AI tool showed up last quarter &#8211; is a different category of investment than a nineteenth binary checkbox. That distinction matters because <a href="https://www.kiteworks.com/cybersecurity-risk-management/ai-data-governance-guide/">AI data governance</a> isn&#8217;t a feature you toggle on top of existing infrastructure; it&#8217;s a design decision, the same way <a href="http://kiteworks.com/risk-compliance-glossary/fips/">FIPS 140-3</a> validated <a href="http://kiteworks.com/secure-file-sharing/public-vs-private-key-encryption/">encryption</a> is a design decision on the DSMS side. One platform doesn&#8217;t solve the equation. An architecture built to answer it does.</p><h3>What to Do Monday Morning</h3><p><span>1. </span>Calculate your own DSMS and AIGMS separately before you calculate anything else. You need both halves of the equation, not a composite guess.</p><p><span>2. </span>Stop routing the next security budget cycle exclusively at DSMS. If your AIGMS is anywhere near the survey mean of 35, that&#8217;s where the marginal dollar returns more.</p><p><span>3. </span>Audit your AI-specific governance capabilities against the 19-capability list &#8211; purpose binding, behavioral monitoring, AI-specific <a href="http://kiteworks.com/risk-compliance-glossary/data-loss-prevention-dlp/">DLP</a>, <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> generation. Most organizations in this survey have deployed under 7 of them.</p><p><span>4. </span>Treat any DSMS-only &#8220;we hardened our security posture&#8221; claim from a vendor or an internal team as half an answer. Ask what it did to the other side of the multiplication.</p><p><span>5. </span>Benchmark against DSMS tier, not just against peer spend. A Tier 3 organization with a stagnant AIGMS is still capped near a DSCRI in the low 30s, no matter how much more it spends inside Tier 3.</p><p>You cannot multiply your way past a zero. The organizations budgeting as if you can are the ones producing this report&#8217;s median score.</p><p><em>Read the full findings in the <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-data-security-compliance-risk-report.pdf">2026 Data Security and Compliance Risk Report</a>.</em></p>]]></content:encoded></item><item><title><![CDATA[CMMC Has Teeth. Defense Contractors Still Scored a 15.]]></title><description><![CDATA[Contractual enforcement was supposed to be the fix for stalled security investment. In the sector that faces it hardest, it isn&#8217;t working yet.]]></description><link>https://kiteworks.substack.com/p/cmmc-has-teeth-defense-contractors</link><guid isPermaLink="false">https://kiteworks.substack.com/p/cmmc-has-teeth-defense-contractors</guid><dc:creator><![CDATA[Patrick Spencer]]></dc:creator><pubDate>Tue, 18 Aug 2026 15:02:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nW3b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nW3b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nW3b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!nW3b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!nW3b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!nW3b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nW3b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:474677,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/211198832?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nW3b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!nW3b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!nW3b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!nW3b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7156f83-9e49-4989-8116-ebd39ec49a1f_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Picture this: it&#8217;s Tuesday morning, and a compliance manager at a mid-tier defense subcontractor is staring at a spreadsheet with 110 rows in it &#8211; the <a href="http://kiteworks.com/risk-compliance-glossary/protect-cui-with-nist-800-171-compliance/">NIST SP 800-171</a> practices a <a href="http://kiteworks.com/risk-compliance-glossary/cmmc-third-party-assessor-organization-c3pao/">C3PAO</a> assessor will check line by line before the company can bid on its next DoD task order, formalized under the <a href="https://dodcio.defense.gov/cmmc/">CMMC Program Final Rule at 32 CFR Part 170</a>. <a href="http://kiteworks.com/secure-file-sharing/secure-file-sharing-with-access-control/">Access control</a>. Audit and accountability. <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">Incident response</a>. System and communications protection. Four categories, 110 controls, one outcome if the assessment fails: no CMMC certification, no contract. Not a strongly worded finding. A canceled bid.</p><p>That is the enforcement mechanism every other sector in the 2026 Data Security and Compliance Risk Report wishes it had. And it is the sector that scored the worst.</p><h3>What the Numbers Actually Say</h3><p>Defense Contractors post a Data Security Maturity Score (DSMS) of 15, the lowest of any of the ten sectors surveyed, more than 16 points below the survey mean of 39, and 28 points below Financial Services at 43.3.</p><p>Fifteen. Read that again.</p><p>Their AI Governance Maturity Score (AIGMS) is 22.8, also the lowest in the survey, nearly 12 points under the AIGMS mean of 34.7. Multiply the two and you get a Data Security and Compliance Readiness Index (DSCRI) of roughly 3.75 (DSMS 15 times AIGMS 25, divided by 100). That is the lowest composite readiness score of any sector measured.</p><p>One caveat, stated plainly because the report states it plainly: the Defense Contractors sample is three respondents. You cannot build an industry benchmark on n=3, and I&#8217;m not going to pretend otherwise. But three data points pointing the same direction, in the one sector facing a contractually enforced mandate, is not a number you get to wave off. It&#8217;s a flare.</p><h3>The Company Defense Contractors Keep</h3><p>Federal Government, the sector with the largest government-adjacent sample and no equivalent contractual teeth, doesn&#8217;t do much better. Its DSMS of 22.7 is the lowest among sectors with a meaningful sample size, more than 16 points below the mean. Its AIGMS of 25.4 is the second lowest in the survey. The <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Kiteworks Data Security and Compliance Risk: 2026 Forecast Report</a>, published in December 2025, called Government &#8220;a generation behind&#8221;: 90% lacking centralized AI gateways, 76% missing kill switches, 90% missing purpose binding. Six months and 459 respondents later, the Annual Survey confirms the profile hasn&#8217;t moved &#8211; a stall consistent with the <a href="https://www.weforum.org/publications/global-cybersecurity-outlook-2026/">World Economic Forum&#8217;s Global Cybersecurity Outlook 2026</a>, which found 87% of cyber leaders identified AI-related <a href="http://kiteworks.com/risk-compliance-glossary/vulnerability/">vulnerabilities</a> as the fastest-growing cyber risk of 2025.</p><p>Here is where the conventional explanation runs out. Federal Government&#8217;s weak showing is easy to explain: AI governance there lives in policy memos, not contracts, and policy without enforcement rarely beats a budget cycle. Defense Contractors don&#8217;t have that excuse. <a href="http://kiteworks.com/platform/compliance/cmmc-compliance/">CMMC 2.0</a> Level 2 is a flow-down clause in the contract, backed by third-party assessment and tied directly to award eligibility. If any framework in this survey should have forced maturity, it&#8217;s this one. It didn&#8217;t.</p><h3>Why a Mandate With Teeth Still Isn&#8217;t Enough</h3><p>The representation analysis makes the failure harder to argue away. Plot every respondent on a DSMS-by-AIGMS grid and you get four quadrants: leaders, two mixed profiles, and laggards. Zero Defense Contractor respondents land in the leadership quadrant. Zero. The sector&#8217;s laggard-quadrant representation index sits at 1.27, meaning contractors show up in the bottom-left corner well above their proportional share. Federal Government&#8217;s laggard index is worse still at 1.70, the highest of any sector with a meaningful sample, against a leadership index of just 0.25.</p><p>Here&#8217;s the whole game: a mandate without enforcement teeth fails to move behavior. That&#8217;s Federal Government, and it&#8217;s exactly what you&#8217;d expect from policy memos competing with budget cycles. But a mandate with real enforcement teeth is failing too. That&#8217;s Defense Contractors, and it is not what anyone modeling CMMC&#8217;s deterrent effect would have predicted.</p><p>Both are true. Both at once. And the second one is the finding that should worry you, because it means contractual teeth alone don&#8217;t guarantee behavior change &#8211; they just change what the failure costs you. Federal Government&#8217;s failure shows up as an audit finding or an IG report. A defense contractor&#8217;s failure shows up as a lost award. Call it enforcement without adoption &#8211; the mandate exists, the penalty is real, and the controls still aren&#8217;t there. That is a categorically different kind of exposure, and a DSMS of 15 says the sector has not internalized it yet.</p><h3>The Architectural Question CMMC Doesn&#8217;t Answer</h3><p>Here&#8217;s the part the compliance spreadsheet misses: 110 discrete <a href="http://kiteworks.com/risk-compliance-glossary/protect-cui-with-nist-800-171-compliance/">NIST SP 800-171</a> practices, assessed individually, tempt organizations into a checklist mentality: prove each control exists in isolation rather than build one governance layer that enforces all of them coherently. <a href="http://kiteworks.com/secure-file-sharing/secure-file-sharing-with-access-control/">Access control</a>, audit and accountability, <a href="http://kiteworks.com/risk-compliance-glossary/incident-response/">incident response</a>, and system and communications protection are exactly the categories the DSMS measures across every sector in this survey, and they are the categories that fragment fastest when sensitive data moves across email, <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer/">MFT</a>, web forms, and a growing list of AI tools with no shared enforcement point.</p><p>This is the argument for treating <a href="http://kiteworks.com/platform/compliance/cmmc-compliance/">CMMC 2.0</a> compliance as an architecture decision rather than a documentation exercise. It matters more now than it did two years ago: <a href="https://www.crowdstrike.com/global-threat-report/">CrowdStrike&#8217;s 2026 Global Threat Report</a> documents AI-enabled adversaries moving laterally in as little as 27 seconds, and <a href="https://cpl.thalesgroup.com/data-threat-report">Thales&#8217; 2026 Data Threat Report</a> finds only 47% of sensitive cloud-resident data is actually <a href="http://kiteworks.com/secure-file-sharing/public-vs-private-key-encryption/">encrypted</a> despite near-universal channel adoption. A checklist assessed once a year cannot keep pace with a threat that moves in seconds, across channels most contractors have never fully inventoried.</p><p>The fix isn&#8217;t another point solution bolted onto the 110-control checklist. It&#8217;s consolidating every channel that carries <a href="http://kiteworks.com/risk-compliance-glossary/cmmc-cui-and-what-it-means/">CUI</a> and FCI &#8211; email, <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer/">MFT</a>, web forms, API traffic &#8211; under one policy enforcement layer with continuous, evidence-quality logging, so the <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> a <a href="http://kiteworks.com/risk-compliance-glossary/cmmc-third-party-assessor-organization-c3pao/">C3PAO</a> wants already exists instead of getting assembled the week before assessment. Enforce the controls centrally and the checklist becomes a byproduct of the architecture, not the goal of it. That&#8217;s the difference between passing an assessment and never having to wonder if you would.</p><h3>What to Do Monday Morning</h3><p>If you sit inside a defense contractor, or anywhere in that supply chain, the DSMS of 15 is not someone else&#8217;s statistic. It&#8217;s a preview of your next assessment if your controls are as fragmented as the sector average suggests.</p><p><span>&#8226; </span>Pull your own DSMS-equivalent tally now: how many of the 11 controls this report measures (encryption, <a href="http://kiteworks.com/risk-compliance-glossary/data-loss-prevention-dlp/">DLP</a> enforcement, <a href="http://kiteworks.com/risk-compliance-glossary/what-is-security-information-and-event-management/">SIEM</a> integration, kill switches, and the rest) are actually deployed, not just documented.</p><p><span>&#8226; </span>Map every channel carrying <a href="http://kiteworks.com/risk-compliance-glossary/cmmc-cui-and-what-it-means/">CUI</a> or FCI &#8211; email, file sharing, <a href="http://kiteworks.com/risk-compliance-glossary/managed-file-transfer/">MFT</a>, forms, API &#8211; against a single point of policy enforcement, not seven.</p><p><span>&#8226; </span>Ask whether your <a href="http://kiteworks.com/regulatory-compliance/audit-log/">audit trail</a> exists because a system generates it continuously, or because someone will assemble it manually the week before assessment.</p><p><span>&#8226; </span>Treat purpose binding and access logging as contract-preservation controls, not nice-to-haves &#8211; they map directly to the <a href="http://kiteworks.com/secure-file-sharing/secure-file-sharing-with-access-control/">access control</a> and audit-and-accountability families a <a href="http://kiteworks.com/risk-compliance-glossary/cmmc-third-party-assessor-organization-c3pao/">C3PAO</a> will test.</p><p><span>&#8226; </span>Stop treating CMMC certification as the finish line. The DSCRI of 3.75 says certification and actual readiness are not the same thing, and only one of them keeps the contract.</p><p>A mandate with real enforcement teeth just proved it isn&#8217;t self-executing. The gap between &#8220;we have a framework&#8221; and &#8220;we have the architecture that satisfies it&#8221; is still yours to close &#8211; and in this sector, the bill for not closing it isn&#8217;t a finding. It&#8217;s the contract.</p><p><em>Read the full findings in the <a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-2026-data-security-compliance-risk-report.pdf">2026 Data Security and Compliance Risk Report</a>.</em></p>]]></content:encoded></item><item><title><![CDATA[China’s New AI Rules Are Now Your Compliance Problem, Too.]]></title><description><![CDATA[Beijing&#8217;s rules stop at the border. The audit trail obligation does not.]]></description><link>https://kiteworks.substack.com/p/chinas-new-ai-rules-are-now-your</link><guid isPermaLink="false">https://kiteworks.substack.com/p/chinas-new-ai-rules-are-now-your</guid><dc:creator><![CDATA[Danielle Barbour]]></dc:creator><pubDate>Mon, 17 Aug 2026 15:02:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WRbZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WRbZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WRbZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!WRbZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!WRbZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!WRbZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WRbZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:516288,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://kiteworks.substack.com/i/211055201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WRbZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png 424w, https://substackcdn.com/image/fetch/$s_!WRbZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png 848w, https://substackcdn.com/image/fetch/$s_!WRbZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png 1272w, https://substackcdn.com/image/fetch/$s_!WRbZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd39a595-a0f9-41ab-9bf7-7ead842a2a34_720x480.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On July 16, 2026, delegates from 29 countries gathered in Shanghai to launch the World AI Cooperation Organization, a new China-headquartered body meant to coordinate global AI governance. Indonesia, Brazil, Malaysia, Russia, Pakistan, Kazakhstan, and two dozen other states signed on as founding members. UN Secretary-General Ant&#243;nio Guterres showed up for the opening. Not one G7 economy did. Neither did the European Union.</p><p>That&#8217;s not actually the story. The story is what happened inside China&#8217;s own regulatory apparatus in the weeks around that launch. Four rule sets and one draft law arrived in a six-week window, and they apply to any multinational with a China subsidiary, a China-based vendor, or a banking relationship touching Chinese financial institutions, regardless of whether that company has ever sold a product inside China&#8217;s borders.</p><p>Here&#8217;s what I keep coming back to: global AI governance stopped converging toward a single standard this year. It&#8217;s splitting into competing blocs, and the fastest-moving one just wrote rules that reach past its own border and land on your desk anyway.</p><h3><span>What Actually Changed in China This Summer</span></h3><p>Start with the mechanics, because they&#8217;re more specific than most &#8220;AI regulation&#8221; coverage suggests. China&#8217;s Interim Measures for the Administration of Anthropomorphic AI Interaction Services took effect July 15, 2026, one day before WAICO&#8217;s launch. The measures require life-cycle <a href="http://kiteworks.com/risk-compliance-glossary/risk-assessment/">risk assessment</a>, ethics review, content monitoring, and incident-response programs for any AI service designed to simulate humanlike interaction. They also mandate a &#8220;minor mode,&#8221; guardian consent with spending and usage limits for users under 14, and an outright ban on virtual companion or virtual-relative services for minors, plus a ban on emotionally manipulative design generally. Several major Chinese platforms suspended roleplay and companion features rather than retrofit compliance in time. That&#8217;s not a symbolic response to a symbolic rule.</p><p>A month earlier, on June 18, China&#8217;s National Financial Regulatory Administration had issued its Guidelines on the Safe Development and Application of AI in Banking and Insurance: 32 principles under seven pillars. Banks and insurers now need risk-control-committee approval before deploying AI for high-risk use cases, cannot use personal information as AI training data, and must file any externally sourced AI model with the Cyberspace Administration of China.</p><p>Layered on top, the CAC published new Q&amp;A guidance clarifying cross-border transfer mechanics: what a valid &#8220;separate consent&#8221; disclosure must contain, how the &#8220;necessity&#8221; test applies to routine transfers like a job candidate&#8217;s CV, and what conditions govern renewing an already-approved transfer. On July 29, China issued a draft national Anti-Cyber Violence Law for public comment, prohibiting deepfakes and profiling-based targeting used to harass. Barbara Li of Reed Smith laid out this whole sequence for <a href="https://iapp.org/news/a/notes-from-the-asia-pacific-region-china-rolls-out-new-ai-governance-data-protection-measures">IAPP&#8217;s Asia-Pacific coverage</a> on August 6, 2026. Read together, it looks less like one policy announcement and more like a regulator tightening several fronts at once.</p><h3><span>The Bloc Problem</span></h3><p>WAICO matters more than a photo-op suggests. Twenty-nine founding member states, a permanent headquarters in Shanghai, a UN Secretary-General in the room. <a href="https://english.www.gov.cn/news/202607/17/content_WS6a59a226c6d00ca5f9a0c432.html">China&#8217;s state media covered the launch</a> as a serious institutional milestone, and <a href="https://thediplomat.com/2026/07/chinas-new-ai-club-the-world-artificial-intelligence-cooperation-organization/">The Diplomat&#8217;s analysis</a> treats it the same way. No G7 economy joined. No EU member joined.</p><p>That absence is the tell. AI governance isn&#8217;t converging toward one rulebook that the EU AI Act, the U.S. approach, and China&#8217;s framework eventually reconcile into. It&#8217;s splitting into parallel systems, and a bloc of large economies including Brazil and Indonesia is aligning with Shanghai rather than Brussels or Washington. If your supply chain, banking relationships, or data flows touch any of those 29 countries, you already stand inside more than one jurisdiction&#8217;s rulebook. Whether your compliance team has mapped that yet is a separate question.</p><h3><span>Why the Math Got Worse</span></h3><p>Fragmentation alone would be a headache. What makes 2026 different is that China&#8217;s new rules attach concrete, auditable evidence requirements to the fragmentation rather than leaving it as broad principle.</p><p>The NFRA banking guidance is the clearest example. &#8220;Don&#8217;t use personal information to train AI models&#8221; and &#8220;file externally sourced models with the CAC&#8221; aren&#8217;t awareness campaigns. They&#8217;re things a regulator can demand you prove, on a specific date, with a specific document trail. The CAC&#8217;s cross-border Q&amp;A doesn&#8217;t loosen the substance of China&#8217;s transfer rules either. It removes the ambiguity that used to let companies argue their way through a gray area, which means clearer rules and fewer places to hide a gap.</p><p>This isn&#8217;t a China-only anxiety. Kiteworks&#8217; <a href="https://www.kiteworks.com/cybersecurity-risk-management/2026-data-security-forecast-ai-governance-predictions/">Data Security and Compliance Risk: 2026 Forecast Report</a> found 34% of organizations already cite cross-border data transfer mechanisms as a top regulatory priority, and 29% cite cross-border transfers through AI vendors as a top privacy exposure, and that&#8217;s before Beijing&#8217;s second, diverging rulebook even entered the picture. One genuine relief valve arrives September 1, 2026: companies processing personal data on fewer than 100,000 individuals qualify in China as &#8220;small-scale personal information handlers,&#8221; with simplified notice, consent, and longer audit cycles. Claiming that exemption still requires knowing your headcount against the threshold, so the <a href="http://kiteworks.com/secure-file-transfer/data-classification-what-it-is-types-and-best-practices/">classification</a> work happens either way.</p><h3><span>The Architectural Question</span></h3><p>Kiteworks doesn&#8217;t sell into China, so there&#8217;s no vendor angle to spin here. The point stands on its own: the exposure created by this summer&#8217;s rules doesn&#8217;t depend on whether your company has a presence in China. It depends on whether data crosses that border at all, personal information, CVs, financial records, model training sets, through a subsidiary, a vendor contract, or a banking relationship. Company presence is the wrong unit of analysis. The data crossing the line is the right one.</p><p>That reframes the response. Chasing each new Chinese regulation with a policy memo doesn&#8217;t scale once you&#8217;re tracking WAICO-aligned states, EU rules, and U.S. state law at the same time. What scales is governing the data itself: <a href="http://kiteworks.com/secure-file-transfer/data-classification-what-it-is-types-and-best-practices/">classification</a> that flags what&#8217;s in scope, geo-conditioned policy that acts on that classification automatically, and audit evidence proving the policy held. Regulators are increasingly asking for exactly this layer. It&#8217;s the same one the 2026 Forecast Report found 33% of organizations still lack in evidence-quality form, a gap tied to measurably lower AI-governance maturity across the board.</p><p>Concretely, that looks like an <a href="http://kiteworks.com/risk-compliance-glossary/attribute-based-access-control/">attribute-based</a> <a href="https://www.kiteworks.com/data-policy-engine-explainer-video/">data policy</a> engine that conditions on a documented value (geolocation &#8220;is&#8221; or &#8220;is not&#8221; China, for instance) and applies a graduated response, block, require approval, tag, or view-only rendering, to send, share, upload, and attach actions across email, file sharing, APIs, SFTP, managed file transfer, and the Secure MCP Server that AI applications use to reach the data. Both the people and the AI agents touching a file sit under that same policy. Neither side goes unmanaged. A separate <a href="http://kiteworks.com/risk-compliance-glossary/data-sovereignty-protecting-our-digital-footprint-in-the-age-of-information/">data sovereignty</a> control that pins a user&#8217;s data to their assigned country, in storage and in transit, with built-in location reporting, gives an auditor something to examine besides a policy document. None of that requires operating in China. It requires governing the border the data crosses.</p><h3><span>What This Means Monday Morning</span></h3><p><span>&#8226; </span>Map every data flow that touches China &#8211; subsidiary, vendor contract, banking relationship, even a candidate&#8217;s CV headed to a China-based recruiter &#8211; before assuming no China office means no exposure.</p><p><span>&#8226; </span>Classify what&#8217;s moving: personal information versus operational data, training data versus everything else. The NFRA rule turns &#8220;was this used to train a model&#8221; into a question you need a documented answer to.</p><p><span>&#8226; </span>Build a geo-conditioned policy for that corridor specifically, not a blanket block that breaks legitimate business.</p><p><span>&#8226; </span>If you bank in China or rely on a China-sourced AI model, confirm your CAC filing status now; that NFRA rule is already in force.</p><p><span>&#8226; </span>Before claiming the September 1 small-scale-handler relief, count. The exemption requires the <a href="http://kiteworks.com/secure-file-transfer/data-classification-what-it-is-types-and-best-practices/">classification</a> work you should be doing anyway.</p><p><span>&#8226; </span>Generate the audit evidence before a regulator asks for it, not after.</p><p>WAICO&#8217;s 29 members and the G7&#8217;s absence make a tidy geopolitics story. The rulebook fragmenting underneath it is the one your auditor will actually ask about.</p><p><em>Danielle Barbour writes on data governance and regulatory strategy for Zero Trust Data Exchange.</em></p>]]></content:encoded></item></channel></rss>